3MF Consortium lib3mf: Remote code execution A vulnerability in lib3mf could lead to remote code execution. lib3mf 2022-08-04 2022-08-04 775362 remote 2.1.1 2.1.1

lib3mf is an implementation of the 3D Manufacturing Format file standard.

Incorrect memory handling within lib3mf could result in a use-after-free.

An attacker that can provide malicious input to an application using 3MF Consortium's lib3mf could achieve remote code execution.

There is no known workaround at this time.

All 3MF Consortium lib3mf users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-libs/lib3mf-2.1.1"
CVE-2021-21772 ajak ajak