Junglewise Threat Intelligence

CVE-2022-38072: PYSEC-2023-263 - An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v

CVE-2022-38072 · Severity: low · CVSS 3.1 · Published 2023-04-03

Technologies: admesh (PyPI). Vendors: PyPI.

Executive brief

An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

Affected products

  • PyPI admesh

Related threats