Multiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file can lead to stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability concerns the header parsing occuring while processing an .off file via the readOFF function.
We can see above that at [0] a stack-based buffer called comment is defined with an hardcoded size of 1000 bytes. The call to fscanf at [1] is unsafe and if the first line of the header of the .off files is longer than 1000 bytes it will overflow the header buffer.
{
"cna_assigner": "talos",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24684.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "v2.5.0"
},
{
"last_affected": "v2.5.0"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-121"
]
}