CVE-2020-28603 - log back

CVE-2020-28603 edited at 04 Mar 2021 23:34:11
Type
- Information disclosure
+ Arbitrary code execution
CVE-2020-28603 created at 04 Mar 2021 23:32:37
Severity
+ Medium
Remote
+ Local
Type
+ Information disclosure
Description
+ A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An out of bounds read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_hedge() e->set_prev(). An attacker can provide malicious input to trigger this vulnerability.
References
+ https://talosintelligence.com/vulnerability_reports/TALOS-2020-1225
Notes