Summary
A crafted 3MF XML document can cause a crash due to a NULL pointer dereference during parsing.
Vulnerable versions
Step to reproduce
- Create the proof-of-concept OBJ file (
3dmodel.3dmodel):
<model>
<resources>
<object id="1">
<mesh>
<vertices>
<vertex />
</vertices>
</mesh>
</object>
</resources>
</model>
- Pack the file into a zip archive together with the prerequisite other files from a 3mf file:
3D/3dmodel.3dmodel
rels/.rels
[Content_Types].xml
- Rename the zip archive to
nullptr_3mf_vertex.3mf
- Execute
slic3r --info nullptr_3mf_vertex.3mf
- Observe segmentation fault.
Example file
nullptr_3mf_vertex.zip
Cause
get_attribute() in TMF.cpp returns NULL if the sought attribute is missing. The NULL check at TMF.cpp:580 is ineffective, since self->stop() does not terminate the current function.
Execution continues to line 582, where atof receives a NULL pointer input, and a crash results.
Impact
Denial of Service.
Proposed mitigation
Throw an exception in TMFParserContext::stop() to ensure that file parsing stops immediately.
Summary
A crafted 3MF XML document can cause a crash due to a NULL pointer dereference during parsing.
Vulnerable versions
Step to reproduce
3dmodel.3dmodel):nullptr_3mf_vertex.3mfslic3r --info nullptr_3mf_vertex.3mfExample file
nullptr_3mf_vertex.zip
Cause
get_attribute()in TMF.cpp returns NULL if the sought attribute is missing. The NULL check at TMF.cpp:580 is ineffective, sinceself->stop()does not terminate the current function.Execution continues to line 582, where
atofreceives a NULL pointer input, and a crash results.Impact
Denial of Service.
Proposed mitigation
Throw an exception in
TMFParserContext::stop()to ensure that file parsing stops immediately.