Updated cgal packages fix security vulnerabilities:
An oob read vulnerability exists in Nef_2/PM_io_parser.h
PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide
malicious input to trigger this vulnerability (CVE-2020-28601).
An oob read vulnerability exists in Nef_S2/SNC_io_parser.h
SNC_io_parser::read_sloop() slh->twin() An attacker can provide malicious
input to trigger this vulnerability (CVE-2020-28636).
An oob read vulnerability exists in Nef_S2/SNC_io_parser.h
SNC_io_parser::read_sloop() slh->incident_sface. An attacker can provide
malicious input to trigger this vulnerability (CVE-2020-35628).
An oob read vulnerability exists in Nef_S2/SNC_io_parser.h
SNC_io_parser::read_sface() sfh->volume(). An attacker can provide malicious
input to trigger this vulnerability (CVE-2020-35636).
- https://bugs.mageia.org/show_bug.cgi?id=28881
- https://lists.debian.org/debian-lts-announce/2021/05/msg00002.html
- https://www.cve.org/CVERecord?id=CVE-2020-28601
- https://www.cve.org/CVERecord?id=CVE-2020-28636
- https://www.cve.org/CVERecord?id=CVE-2020-35628
- https://www.cve.org/CVERecord?id=CVE-2020-35636
- 7/core/cgal-4.14-1.1.mga7
Get the latest Linux and open source security news straight to your inbox.