CVE-2022-0496

Source
https://cve.org/CVERecord?id=CVE-2022-0496
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-0496.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-0496
Downstream
Related
Published
2022-08-29T14:03:04Z
Modified
2026-07-22T01:09:52.853526Z
Summary
[none]
Details

A vulnerbiility was found in Openscad, where a DXF-format drawing with particular (not necessarily malformed!) properties may cause an out-of-bounds memory access when imported using import().

Database specific
{
    "cwe_ids": [
        "CWE-119"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0496.json",
    "cna_assigner": "redhat",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "Not-Known."
                },
                {
                    "last_affected": "Not-Known."
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/openscad/openscad

Affected ranges

Type
GIT
Repo
https://github.com/openscad/openscad
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

openscad-2010.*
openscad-2010.02
openscad-2013.*
openscad-2013.01
openscad-2013.06
openscad-2019.*
openscad-2019.01-RC1
openscad-2019.01-RC2
openscad-2019.01-RC3
openscad-2019.01-RC4
openscad-2019.05
openscad-2020.*
openscad-2020.12-RC1
openscad-2020.12-RC2
openscad-2020.12-RC3
openscad-2020.12-RC4
openscad-2021.*
openscad-2021.01
openscad-2021.01-RC5
openscad-2021.01-RC6

Database specific

vanir_signatures_modified
"2026-07-22T01:09:52Z"
vanir_signatures
[
    {
        "signature_type": "Line",
        "target": {
            "file": "src/dxfdata.cc"
        },
        "deprecated": false,
        "source": "https://github.com/openscad/openscad/commit/770e3234cbfe66edbc0333f796b46d36a74aa652",
        "id": "CVE-2022-0496-168e8f09",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "104840646302914985118028507586666679707",
                "290192162864074042858498841783119365612",
                "129351661344461194091528965916417341165",
                "202708110383139101075653018937083936016",
                "69174987949301901940964503180918080048",
                "271101462915753809679981024044093574209",
                "36379956317467065235078098124512951203",
                "111464875205028175271107682248788448728",
                "219379521138952918494047257993133227178",
                "331532785697622192092237433826546804796",
                "244017198212517058412015092303819341423",
                "56081805150064249445818754292008390736",
                "337181698592156043535468985986190304910",
                "175219831185231836785725466039276036509",
                "282901159936443623880124927469027667030",
                "69174987949301901940964503180918080048",
                "271101462915753809679981024044093574209",
                "36379956317467065235078098124512951203",
                "111464875205028175271107682248788448728",
                "219379521138952918494047257993133227178",
                "7016578426519698825768555908807306373",
                "121421248718489684711849881019924788079",
                "41520838851822563568603610678022585120",
                "63866660630917595136451409211490921174",
                "175219831185231836785725466039276036509",
                "292643001473904189793602732371252989260"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "src/dxfdata.cc"
        },
        "deprecated": false,
        "source": "https://github.com/openscad/openscad/commit/00a4692989c4e2f191525f73f24ad8727bacdf41",
        "id": "CVE-2022-0496-2d218215",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "104840646302914985118028507586666679707",
                "290192162864074042858498841783119365612",
                "129351661344461194091528965916417341165",
                "202708110383139101075653018937083936016",
                "69174987949301901940964503180918080048",
                "271101462915753809679981024044093574209",
                "36379956317467065235078098124512951203",
                "111464875205028175271107682248788448728",
                "219379521138952918494047257993133227178",
                "331532785697622192092237433826546804796",
                "244017198212517058412015092303819341423",
                "56081805150064249445818754292008390736",
                "337181698592156043535468985986190304910",
                "175219831185231836785725466039276036509",
                "282901159936443623880124927469027667030",
                "69174987949301901940964503180918080048",
                "271101462915753809679981024044093574209",
                "36379956317467065235078098124512951203",
                "111464875205028175271107682248788448728",
                "219379521138952918494047257993133227178",
                "7016578426519698825768555908807306373",
                "121421248718489684711849881019924788079",
                "41520838851822563568603610678022585120",
                "63866660630917595136451409211490921174",
                "175219831185231836785725466039276036509",
                "292643001473904189793602732371252989260"
            ],
            "threshold": 0.9
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-0496.json"