VDB

CVE-2021-21772

CVE-2021-21772 PUBLISHED

A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

EPSS 1.67% · 82.5th percentile

Risk Scores

EPSS Score
1.67%
82.5th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlib3mf0, 1.8.1+ds-3

Timeline

  • Mar 10, 2021 CVE Published
  • Apr 14, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Dec 29, 2022 EPSS Score
  • Feb 22, 2023 EPSS Score
  • Mar 11, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›