CVE-2022-38072
published 2023-04-03CVE-2022-38072: An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A…
PriorityP342high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.06%
61.3th percentile
An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| admesh | admesh | — | — |
| admesh | admesh | — | — |
| admesh_project | admesh | — | — |
| admesh_project | admesh | — | — |
| admesh_project | admesh | >= 0 < 0.98.5-1 | 0.98.5-1 |
| admesh_project | admesh | >= 0 < 0.98.5-1 | 0.98.5-1 |
| admesh_project | admesh | >= 0 < 0.98.5 | 0.98.5 |
| debian | admesh | < admesh 0.98.5-1 (forky) | admesh 0.98.5-1 (forky) |
| slic3r | libslic3r | — | — |
| slic3r | libslic3r | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
ADMesh improper array index validation
ghsa·2023-04-03
CVE-2022-38072 [HIGH] CWE-118 ADMesh improper array index validation
ADMesh improper array index validation
An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
OSV
ADMesh improper array index validation
osv·2023-04-03
CVE-2022-38072 [HIGH] ADMesh improper array index validation
ADMesh improper array index validation
An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
OSV
CVE-2022-38072: An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0
osv·2023-04-03·CVSS 8.8
CVE-2022-38072 [HIGH] CVE-2022-38072: An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0
An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Debian
CVE-2022-38072: admesh - An improper array index validation vulnerability exists in the stl_fix_normal_di...
vendor_debian·2022·CVSS 6.5
CVE-2022-38072 [MEDIUM] CVE-2022-38072: admesh - An improper array index validation vulnerability exists in the stl_fix_normal_di...
An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 0.98.5-1)
sid: resolved (fixed in 0.98.5-1)
trixie: resolved (fixed in 0.98.5-1)
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Buffer overflow vulnerability in ADMesh library
blogs_talos·2023-04-03·CVSS 6.5
CVE-2022-38072 [MEDIUM] Vulnerability Spotlight: Buffer overflow vulnerability in ADMesh library
Francesco Benvenuto of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered an improper array index validation vulnerability in a functionality of the ADMesh library.
ADMesh is a C library used to process 3-D triangular meshes.
Talos found an improper array index validation vulnerability in TALOS-2022-1594 (CVE-2022-38072). A specially crafted STL file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Cisco Talos worked with ADMesh to ensure that this issue was resolved and an update is available for affected customers, all in adherence to Cisco’s vulnerability disclosure policy.
Users are encouraged to update these affected products as soon as possible: ADMesh Master Commit 767a105, Slic3r libslic3r Maste
Talos
Vulnerability Spotlight: Buffer overflow vulnerability in ADMesh library
blogs_talos·2023-04-03·CVSS 6.5
CVE-2022-38072 [MEDIUM] Vulnerability Spotlight: Buffer overflow vulnerability in ADMesh library
## Vulnerability Spotlight: Buffer overflow vulnerability in ADMesh library
Francesco Benvenuto of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered an improper array index validation vulnerability in a functionality of the ADMesh library.
ADMesh is a C library used to process 3-D triangular meshes.
Talos found an improper array index validation vulnerability in TALOS-2022-1594 (CVE-2022-38072). A specially crafted STL file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Cisco Talos worked with ADMesh to ensure that this issue was resolved and an update is available for affected customers, all in adherence to Cisco’s vulnerability disclosure policy .
Users are encouraged to update these affected prod
https://github.com/admesh/admesh/commit/5fab257268a0ee6f832c18d72af89810a29fbd5fhttps://talosintelligence.com/vulnerability_reports/TALOS-2022-1594https://github.com/admesh/admesh/commit/5fab257268a0ee6f832c18d72af89810a29fbd5fhttps://talosintelligence.com/vulnerability_reports/TALOS-2022-1594https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1594
2023-04-03
Published