Vulnerability Details CVE-2020-28622
Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_edge() eh->incident_sface().
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.9%
CVSS Severity
CVSS v3 Score 10.0
CVSS v2 Score 6.8
Products affected by CVE-2020-28622
-
cpe:2.3:a:cgal:computational_geometry_algorithms_library:5.1.1
-
cpe:2.3:o:debian:debian_linux:10.0