MGASA-2021-0276

Source
https://advisories.mageia.org/MGASA-2021-0276.html
Import Source
https://advisories.mageia.org/MGASA-2021-0276.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0276
Related
Published
2021-06-23T17:11:28Z
Modified
2021-06-23T15:26:07Z
Summary
Updated slic3r package fixes a security vulnerability
Details

An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted AMF file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability (CVE-2020-28591).

References
Credits

Affected packages

Mageia:8 / slic3r

Package

Name
slic3r
Purl
pkg:rpm/mageia/slic3r?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.0-6.1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / slic3r

Package

Name
slic3r
Purl
pkg:rpm/mageia/slic3r?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.0-1.1.mga7

Ecosystem specific

{
    "section": "core"
}