|
|
Log in / Subscribe / Register

Ubuntu alert USN-6216-1 (lib3mf)

From:  Jorge Sancho Larraz <jorge.sancho.larraz@canonical.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-6216-1] lib3mf vulnerability
Date:  Wed, 12 Jul 2023 20:34:23 +0200
Message-ID:  <a879e4ca-708a-e055-9785-aff0b7240759@canonical.com>

========================================================================== Ubuntu Security Notice USN-6216-1 July 11, 2023 lib3mf vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: lib3mf could be made to execute arbitrary code if it opens a specially crafted 3MF file. Software Description: - lib3mf: Lib3MF is a C++ implementation of the 3D Manufacturing Format Details: It was discovered that lib3mf did not properly manage memory under certain circumstances. If a user were tricked into opening a specially crafted 3MF file, a local attacker could possibly use this issue to cause applications using lib3mf to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS:   lib3mf-dev                      1.8.1+ds-3ubuntu0.2   lib3mf1                         1.8.1+ds-3ubuntu0.2 In general, a standard system update will make all the necessary changes. References:   https://ubuntu.com/security/notices/USN-6216-1   CVE-2021-21772 Package Information:   https://launchpad.net/ubuntu/+source/lib3mf/1.8.1+ds-3ubu...


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds