2022-06-24
ALT-BU-2022-5286-1
Branch p10 update bulletin.
Closed vulnerabilities
Published: 2022-08-29
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2022-0496
A vulnerbiility was found in Openscad, where a DXF-format drawing with particular (not necessarily malformed!) properties may cause an out-of-bounds memory access when imported using import().
Severity: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
References:
- https://bugzilla.redhat.com/show_bug.cgi?id=2050695
- https://bugzilla.redhat.com/show_bug.cgi?id=2050695
- https://github.com/openscad/openscad/commit/00a4692989c4e2f191525f73f24ad8727bacdf41
- https://github.com/openscad/openscad/commit/00a4692989c4e2f191525f73f24ad8727bacdf41
- https://github.com/openscad/openscad/commit/770e3234cbfe66edbc0333f796b46d36a74aa652
- https://github.com/openscad/openscad/commit/770e3234cbfe66edbc0333f796b46d36a74aa652
- https://github.com/openscad/openscad/issues/4037
- https://github.com/openscad/openscad/issues/4037
Published: 2022-08-29
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2022-0497
A vulnerbiility was found in Openscad, where a .scad file with no trailing newline could cause an out-of-bounds read during parsing of annotations.
Severity: HIGH (7.1)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
References: