PYSEC-2023-263
Withdrawn 2024-11-22. This finding no longer applies and is kept for reference. It is not used when checking packages.
Quick fix
PYSEC-2023-263 — admesh: upgrade to the fixed version with the command below.
pip install --upgrade 'admesh>=5fab257268a0ee6f832c18d72af89810a29fbd5f'Details
An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/admesh
Introduced in:
0Fixed in: 5fab257268a0ee6f832c18d72af89810a29fbd5fFix
pip install --upgrade 'admesh>=5fab257268a0ee6f832c18d72af89810a29fbd5f'