CVE-2023-35952

NameCVE-2023-35952
DescriptionMultiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker can arbitrary code execution to trigger these vulnerabilities.This vulnerability exists within the code responsible for parsing comments within the geometric faces section within an OFF file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

NOT-FOR-US: libigl
slic3r-prusa bundles a copy, but it's not used for reading files
https://github.com/prusa3d/PrusaSlicer/issues/12905 and #1074233
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1784
https://github.com/libigl/libigl/issues/2387

Search for package or bug name: Reporting problems