CVE-2020-28594

medium
Published — · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk
5.5

Description

A use-after-free vulnerability exists in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2020-28594 NameCVE-2020-28594 DescriptionA use-after-free vulnerability exists in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian…

CVE-2020-28594

NameCVE-2020-28594
DescriptionA use-after-free vulnerability exists in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1074415

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
slic3r-prusa (PTS)bullseye2.3.0+dfsg-1vulnerable
bookworm2.5.0+dfsg-4vulnerable
trixie2.9.2+dfsg-1vulnerable
forky, sid2.9.5+dfsg-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
slic3r-prusasource(unstable)(unfixed)1074415

Notes

[trixie] - slic3r-prusa <postponed> (Minor issue, revisit when fixed upstream)
[bookworm] - slic3r-prusa <postponed> (Minor issue, revisit when fixed upstream)
[bullseye] - slic3r-prusa <no-dsa> (Minor issue)
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1218

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[trixie] - slic3r-prusa <postponed> (Minor issue, revisit when fixed upstream)[bookworm] - slic3r-prusa <postponed> (Minor issue, revisit when fixed upstream)[bullseye] - slic3r-prusa <no-dsa> (Minor issue)https://talosintelligence.com/vulnerability_reports/TALOS-2020-1218

OS impact

arch Arch Affected 1 release
VersionStatusFixed in
Affected
debian Debian Affected 5 releases
VersionStatusFixed in
trixie Affected
sid Affected
forky Affected
bullseye Affected
bookworm Affected

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.