CVE-2021-21772
published 2021-03-10CVE-2021-21772: A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file…
PriorityP347high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
4.34%
90.1th percentile
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 3mf | lib3mf | — | — |
| 3mf | lib3mf | >= 0 < 1.8.1+ds-4 | 1.8.1+ds-4 |
| 3mf | lib3mf | >= 0 < 1.8.1+ds-4 | 1.8.1+ds-4 |
| 3mf | lib3mf | >= 0 < 1.8.1+ds-4 | 1.8.1+ds-4 |
| 3mf | lib3mf | >= 0 < 1.8.1+ds-4 | 1.8.1+ds-4 |
| debian | debian_linux | — | — |
| debian | lib3mf | < lib3mf 1.8.1+ds-4 (bookworm) | lib3mf 1.8.1+ds-4 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6f4r-f2fv-g8f4: A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2
ghsa_unreviewed·2022-05-24
CVE-2021-21772 [HIGH] CWE-416 GHSA-6f4r-f2fv-g8f4: A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
OSV
CVE-2021-21772: A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2
osv·2021-03-10·CVSS 8.1
CVE-2021-21772 [HIGH] CVE-2021-21772: A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Ubuntu
lib3mf vulnerability
vendor_ubuntu·2023-07-11
CVE-2021-21772 lib3mf vulnerability
Title: lib3mf vulnerability
Summary: lib3mf could be made to execute arbitrary code if it opens a specially crafted 3MF file.
It was discovered that lib3mf did not properly manage memory under
certain circumstances. If a user were tricked into opening a specially
crafted 3MF file, a local attacker could possibly use this issue to
cause applications using lib3mf to crash, resulting in a denial of
service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-21772: lib3mf - A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP(...
vendor_debian·2021·CVSS 8.1
CVE-2021-21772 [HIGH] CVE-2021-21772: lib3mf - A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP(...
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 1.8.1+ds-4)
bullseye: resolved (fixed in 1.8.1+ds-4)
forky: resolved (fixed in 1.8.1+ds-4)
sid: resolved (fixed in 1.8.1+ds-4)
trixie: resolved (fixed in 1.8.1+ds-4)
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Use-after-free vulnerability in 3MF Consortium lib3mf
blogs_talos·2021-03-10·CVSS 8.1
[HIGH] Vulnerability Spotlight: Use-after-free vulnerability in 3MF Consortium lib3mf
## Vulnerability Spotlight: Use-after-free vulnerability in 3MF Consortium lib3mf
Lilith >_> of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
3MF Consortium’s lib3mf library is vulnerable to a use-after-free vulnerability that could allow an adversary to execute remote code on the victim machine. The lib3mf library is an open-source implementation of the 3MF file format and standard, mainly used for 3D-printing. An attacker could send a target a specially crafted file to create a use-after-free condition. The 3MF standard has been adopted in a variety of products and lib3mf itself has been confirmed to be used in open-source programs like OpenSCAD and LibCGAL.
In accordance with our coordinated disclosure policy, Cisco Talos worked with 3MF Consortium to ensure that th
Talos
Vulnerability Spotlight: Use-after-free vulnerability in 3MF Consortium lib3mf
blogs_talos·2021-03-10·CVSS 8.1
[HIGH] Vulnerability Spotlight: Use-after-free vulnerability in 3MF Consortium lib3mf
Lilith >_> of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
3MF Consortium’s lib3mf library is vulnerable to a use-after-free vulnerability that could allow an
adversary to execute remote code on the victim machine. The lib3mf library is an open-source implementation of the 3MF file format and standard, mainly used for 3D-printing. An attacker could send a target a specially crafted file to create a use-after-free condition. The 3MF standard has been adopted in a variety of products and lib3mf itself has been confirmed to be used in open-source programs like OpenSCAD and LibCGAL.
In accordance with our coordinated disclosure policy, Cisco Talos worked with 3MF Consortium to ensure that this issue is resolved and that an update is available for affected customers.
## Vu
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IHMMHD2EOMIVJ7EKZTJJMX4C7E6ZRWDL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPBS642OYVA6DUKK3HZHEINVWEDZSMEU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDGGB65YBQL662M3MOBNNJJNRNURW4TG/https://security.gentoo.org/glsa/202208-01https://talosintelligence.com/vulnerability_reports/TALOS-2020-1226https://www.debian.org/security/2021/dsa-4887https://www.talosintelligence.com/vulnerability_reports/TALOS-2021-1226https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IHMMHD2EOMIVJ7EKZTJJMX4C7E6ZRWDL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPBS642OYVA6DUKK3HZHEINVWEDZSMEU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDGGB65YBQL662M3MOBNNJJNRNURW4TG/https://security.gentoo.org/glsa/202208-01https://talosintelligence.com/vulnerability_reports/TALOS-2020-1226https://www.debian.org/security/2021/dsa-4887https://www.talosintelligence.com/vulnerability_reports/TALOS-2021-1226
2021-03-10
Published