CVE-2021-21772 log
Source |
|
Severity | Medium |
Remote | No |
Type | Arbitrary code execution |
Description | A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-1670 | lib3mf-1 | 1.8.1-5 | 1.8.1-6 | Medium | Fixed |