CVE-2022-38072

An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Range Error
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 62.29%
Affected Products (NVD)
VendorProductVersion
admesh_projectadmesh
0.98.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
admesh
bookworm
no-dsa
bullseye
postponed
forky
0.98.5-1
fixed
sid
0.98.5-1
fixed
trixie
0.98.5-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
admesh
bionic
needed
focal
needed
jammy
needed
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needs-triage
oracular
ignored
plucky
ignored
questing
ignored
resolute
needs-triage
trusty
ignored
xenial
ignored