CVE-2021-44961

A memory leakage flaw exists in the class PerimeterGenerator of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. Specially crafted stl files can exhaust available memory. An attacker can provide malicious files to trigger this vulnerability.
References
Link Resource
http://libslic3r.com Broken Link
http://slic3r.com Not Applicable
https://hackmd.io/nDT_UKLyRQendxDwil9A4w Exploit Third Party Advisory
http://libslic3r.com Broken Link
http://slic3r.com Not Applicable
https://hackmd.io/nDT_UKLyRQendxDwil9A4w Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:slic3r:libslic3r:1.3.0:*:*:*:*:*:*:*

History

21 Nov 2024, 06:31

Type Values Removed Values Added
References () http://libslic3r.com - Broken Link () http://libslic3r.com - Broken Link
References () http://slic3r.com - Not Applicable () http://slic3r.com - Not Applicable
References () https://hackmd.io/nDT_UKLyRQendxDwil9A4w - Exploit, Third Party Advisory () https://hackmd.io/nDT_UKLyRQendxDwil9A4w - Exploit, Third Party Advisory

08 Mar 2022, 20:10

Type Values Removed Values Added
References (MISC) http://slic3r.com - (MISC) http://slic3r.com - Not Applicable
References (MISC) https://hackmd.io/nDT_UKLyRQendxDwil9A4w - (MISC) https://hackmd.io/nDT_UKLyRQendxDwil9A4w - Exploit, Third Party Advisory
References (MISC) http://libslic3r.com - (MISC) http://libslic3r.com - Broken Link
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 5.5
CWE CWE-401
CPE cpe:2.3:a:slic3r:libslic3r:1.3.0:*:*:*:*:*:*:*

03 Mar 2022, 03:15

Type Values Removed Values Added
Summary A memory leakage flaw exists in the class PerimeterGenerator of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. A Specially crafAn out-of-bounds read vulnerability exists in the GCode::extrude() functionality of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. A specially crafted stl file could lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.ted stl files can exhaust available memory. A memory leakage flaw exists in the class PerimeterGenerator of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. Specially crafted stl files can exhaust available memory. An attacker can provide malicious files to trigger this vulnerability.

01 Mar 2022, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-01 02:15

Updated : 2024-11-21 06:31


NVD link : CVE-2021-44961

Mitre link : CVE-2021-44961

CVE.ORG link : CVE-2021-44961


JSON object : View

Products Affected

slic3r

  • libslic3r
CWE
CWE-401

Missing Release of Memory after Effective Lifetime