Oval Definition:oval:org.opensuse.security:def:202028600
Revision Date:2022-05-22Version:1
Title:CVE-2020-28600
Description:

An out-of-bounds write vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2020-28600
SUSE CVE-2020-28600
openSUSE-SU-2021:1024-1
openSUSE-SU-2021:1158-1
Platform(s):openSUSE Leap 15.2
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Storage 7
SUSE Manager Proxy 4.1
SUSE Manager Server 4.1
SUSE Package Hub for SUSE Linux Enterprise 15 SP2
Product(s):
Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • openscad-2019.05-lp152.2.3.1 is installed
  • AND openscad is signed with openSUSE key
  • Definition Synopsis
  • SUSE Package Hub for SUSE Linux Enterprise 15 SP2 is installed
  • AND openscad-2019.05-bp152.2.3.1 is installed
  • BACK