Bug 1184978 - (CVE-2020-35628) VUL-0: CVE-2020-35628: cgal: code execution vulnerability may lead to oob read
(CVE-2020-35628)
VUL-0: CVE-2020-35628: cgal: code execution vulnerability may lead to oob read
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.2
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Michael Vetter
Security Team bot
https://smash.suse.de/issue/279207/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-04-19 15:04 UTC by Alexandros Toptsoglou
Modified: 2021-06-02 08:33 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2021-04-19 15:04:03 UTC
CVE-2020-35628

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->incident_sface. An attacker can provide malicious input to trigger this vulnerability.

External Reference:

https://talosintelligence.com/vulnerability_reports/TALOS-2020-1225

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1939905
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-35628
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35628
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1225
Comment 2 Michael Vetter 2021-04-22 12:50:03 UTC
Upstream issue: https://github.com/CGAL/cgal/issues/5345
Upstream fix https://github.com/CGAL/cgal/pull/5371

SR#887551 to graphics/cgal waiting for approval
Comment 3 OBSbugzilla Bot 2021-04-22 14:50:09 UTC
This is an autogenerated message for OBS integration:
This bug (1184978) was mentioned in
https://build.opensuse.org/request/show/887807 15.2 / cgal
https://build.opensuse.org/request/show/887808 Backports:SLE-15-SP3 / cgal
Comment 4 Michael Vetter 2021-06-02 08:33:01 UTC
SRs accepted.