CVE Vulnerabilities

CVE-2021-45847

NULL Pointer Dereference

Published: Jan 25, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Several missing input validations in the 3MF parser component of Slic3r libslic3r 1.3.0 can each allow an attacker to cause an application crash using a crafted 3MF input file.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Slic3rSlic3r1.3.0 (including)1.3.0 (including)
Slic3rUbuntubionic*
Slic3rUbuntufocal*
Slic3rUbuntuimpish*
Slic3rUbuntukinetic*
Slic3rUbuntulunar*
Slic3rUbuntumantic*
Slic3rUbuntuoracular*
Slic3rUbuntuplucky*
Slic3rUbuntutrusty*
Slic3rUbuntuxenial*

Potential Mitigations

References