Bugzilla – Bug 1195568
VUL-0: CVE-2022-0496: openscad: Out-of-bounds memory access in DXF loader
Last modified: 2022-02-07 08:51:51 UTC
rh#2050695 A DXF-format drawing with particular (not necessarily malformed!) properties may cause an out-of-bounds memory access when imported using import(). References: https://github.com/openscad/openscad/issues/4037 References: https://bugzilla.redhat.com/show_bug.cgi?id=2050695 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-0496
Affected: - openSUSE:Backports:SLE-15-SP3:Update - openSUSE:Backports:SLE-15-SP4:Update - openSUSE:Factory There is no patch for this issue yet.
This is an autogenerated message for OBS integration: This bug (1195568) was mentioned in https://build.opensuse.org/request/show/951960 15.3 / openscad
Fixed in: https://github.com/openscad/openscad/commit/770e3234cbfe66edbc0333f796b46d36a74aa652
(In reply to Carlos López from comment #3) > Fixed in: > https://github.com/openscad/openscad/commit/ > 770e3234cbfe66edbc0333f796b46d36a74aa652 I already submitted a fix yesterday: > https://build.opensuse.org/request/show/951960 The upstream developer responsible for the fix happens to be a friend of mine :-).