CVE-2021-21772 - log back

CVE-2021-21772 edited at 03 Apr 2021 10:07:18
References
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1226
+ https://github.com/3MFConsortium/lib3mf/issues/254
+ https://github.com/3MFConsortium/lib3mf/commit/6ac5f521f0a3e9f100814f515e380859c9a6ec46
CVE-2021-21772 edited at 10 Mar 2021 22:12:48
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary code execution
Description
+ A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
References
+ https://talosintelligence.com/vulnerability_reports/TALOS-2020-1226
Notes
CVE-2021-21772 created at 10 Mar 2021 22:12:14