Vulnerability Description
A vulnerbiility was found in Openscad, where a DXF-format drawing with particular (not necessarily malformed!) properties may cause an out-of-bounds memory access when imported using import().
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openscad | Openscad | < 2022-02-04 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2050695Issue TrackingThird Party Advisory
- https://github.com/openscad/openscad/commit/00a4692989c4e2f191525f73f24ad8727bacPatchThird Party Advisory
- https://github.com/openscad/openscad/commit/770e3234cbfe66edbc0333f796b46d36a74aPatchThird Party Advisory
- https://github.com/openscad/openscad/issues/4037ExploitIssue TrackingPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=2050695Issue TrackingThird Party Advisory
- https://github.com/openscad/openscad/commit/00a4692989c4e2f191525f73f24ad8727bacPatchThird Party Advisory
- https://github.com/openscad/openscad/commit/770e3234cbfe66edbc0333f796b46d36a74aPatchThird Party Advisory
- https://github.com/openscad/openscad/issues/4037ExploitIssue TrackingPatch
FAQ
What is CVE-2022-0496?
CVE-2022-0496 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A vulnerbiility was found in Openscad, where a DXF-format drawing with particular (not necessarily malformed!) properties may cause an out-of-bounds memory access when imported using import().
How severe is CVE-2022-0496?
CVE-2022-0496 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0496?
Check the references section above for vendor advisories and patch information. Affected products include: Openscad Openscad.