FS#70052 - [openscad] [Security] arbitrary code execution (CVE-2020-28599)
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Thursday, 18 March 2021, 10:59 GMT
Last edited by Kyle Keen (keenerd) - Wednesday, 14 April 2021, 09:57 GMT
Opened by Jonas Witschel (diabonas) - Thursday, 18 March 2021, 10:59 GMT
Last edited by Kyle Keen (keenerd) - Wednesday, 14 April 2021, 09:57 GMT
|
Details
Summary
======= The package openscad is vulnerable to arbitrary code execution via CVE-2020-28599. Guidance ======== Upgrading OpenSCAD to the latest stable version 2021.01 fixes the issue. References ========== https://security.archlinux.org/AVG-1622 https://talosintelligence.com/vulnerability_reports/TALOS-2020-1223 https://github.com/openscad/openscad/pull/3611 https://github.com/openscad/openscad/commit/07ea60f82e94a155f4926f17fad8e8366bc74874 |
This task depends upon
Closed by Kyle Keen (keenerd)
Wednesday, 14 April 2021, 09:57 GMT
Reason for closing: Fixed
Additional comments about closing: openscad 2021.01-1
Wednesday, 14 April 2021, 09:57 GMT
Reason for closing: Fixed
Additional comments about closing: openscad 2021.01-1