Bug 1184973 - (CVE-2020-28601) VUL-0: CVE-2020-28601: cgal: code execution vulnerability may lead to oob read
(CVE-2020-28601)
VUL-0: CVE-2020-28601: cgal: code execution vulnerability may lead to oob read
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.2
Other Other
: P3 - Medium : Major (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/279202/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-04-19 14:49 UTC by Alexandros Toptsoglou
Modified: 2021-06-02 08:32 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2021-04-19 14:49:47 UTC
CVE-2020-28601

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide malicious input to trigger this vulnerability.

External Reference:

https://talosintelligence.com/vulnerability_reports/TALOS-2020-1225

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1939901
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-28601
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28601
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1225
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E4J344OKKDLPRN422OYRR46HDEN6MM6P/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NB5SF5OJR2DSV7CC6U7FVW5VJSJO5EKV/
Comment 2 Michael Vetter 2021-04-22 12:49:02 UTC
Upstream issue: https://github.com/CGAL/cgal/issues/5345
Upstream fix https://github.com/CGAL/cgal/pull/5371

SR#887551 to graphics/cgal waiting for approval
Comment 3 Michael Vetter 2021-04-22 12:50:08 UTC
Upstream issue: https://github.com/CGAL/cgal/issues/5345
Upstream fix https://github.com/CGAL/cgal/pull/5371

SR#887551 to graphics/cgal waiting for approval
Comment 4 OBSbugzilla Bot 2021-04-22 14:50:03 UTC
This is an autogenerated message for OBS integration:
This bug (1184973) was mentioned in
https://build.opensuse.org/request/show/887807 15.2 / cgal
https://build.opensuse.org/request/show/887808 Backports:SLE-15-SP3 / cgal
Comment 5 Michael Vetter 2021-06-02 08:32:15 UTC
SRs accepted.