Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security bug #60

Closed
Talos-Martin opened this issue Sep 7, 2022 · 5 comments
Closed

Security bug #60

Talos-Martin opened this issue Sep 7, 2022 · 5 comments

Comments

@Talos-Martin
Copy link

Dear ADMesh developers

One of our engineers found a security bug in ADMesh. Where to send the report to?

Regards,

Cisco Talos
https://www.talosintelligence.com/

@gladk
Copy link
Contributor

gladk commented Sep 7, 2022

Hi Martin, I am a Debian maintainer of this software. Please send me an email (you will find it on the linked page). Feel free to encrypt it with the key BBBD45EA818AB86FF67E7285D3E17383CFA7FF06.

We will try to fix it, request a CVE and fix older distributions if affected also.

Thanks!

@Talos-Martin
Copy link
Author

Talos-Martin commented Sep 8, 2022 via email

@gladk
Copy link
Contributor

gladk commented Sep 8, 2022

Yes, exactly.

gladk added a commit that referenced this issue Nov 17, 2022
@hroncok
Copy link
Member

hroncok commented Nov 18, 2022

Thanks for the fix.

@maltfield
Copy link

maltfield commented Jul 25, 2024

@Talos-Martin @gladk Can you please publish the maliciously-crafted .stl file that could be used to trigger the heap buffer overflow in this vulnerability?

Our org is looking into a way to scan and/or sanitize user-contributed .stl files, so having an example of a known-malicious .stl file would help us know what to look for.

Since it's been over a year since the details were publicly announced, I think it would be safe to disclose.

Please upload the maliciously-crafted .stl file (in plaintext), so that we can study it to better understand how to sanitize .stl files.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants