CVE Vulnerabilities

CVE-2022-38072

Incorrect Access of Indexable Resource ('Range Error')

Published: Apr 03, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

Weakness

The product does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed using an index or pointer, such as memory or files.

Affected Software

NameVendorStart VersionEnd Version
AdmeshAdmesh_project0.98.4 (including)0.98.4 (including)
AdmeshAdmesh_project2022-11-18 (including)2022-11-18 (including)
AdmeshUbuntubionic*
AdmeshUbuntuesm-apps/bionic*
AdmeshUbuntuesm-apps/focal*
AdmeshUbuntuesm-apps/jammy*
AdmeshUbuntuesm-apps/xenial*
AdmeshUbuntufocal*
AdmeshUbuntujammy*
AdmeshUbuntukinetic*
AdmeshUbuntulunar*
AdmeshUbuntumantic*
AdmeshUbuntuoracular*
AdmeshUbuntuplucky*
AdmeshUbuntutrusty*
AdmeshUbuntuxenial*

References