VDB
Sign up

PYSEC-2023-263

Withdrawn 2024-11-22. This finding no longer applies and is kept for reference. It is not used when checking packages.

Quick fix

PYSEC-2023-263 — admesh: upgrade to the fixed version with the command below.

pip install --upgrade 'admesh>=5fab257268a0ee6f832c18d72af89810a29fbd5f'

Details

An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/admesh
Introduced in: 0Fixed in: 5fab257268a0ee6f832c18d72af89810a29fbd5f
Fixpip install --upgrade 'admesh>=5fab257268a0ee6f832c18d72af89810a29fbd5f'

References