An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
| Software | From | Fixed in |
|---|---|---|
| admesh_project / admesh | 0.98.4 | 0.98.4.x |
| admesh_project / admesh | 2022-11-18 | 2022-11-18.x |
| slic3r / libslic3r | b1a5500 | b1a5500.x |