CVE-2020-28599: Fedoraproject Fedora
High severity, CVSS 7.8. EPSS: 2% chance of exploitation in the next 30 days.
A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected products
- Fedoraproject Fedora: version 32 only; version 33 only
- Openscad Openscad: up to and including 2021.01
Published 2021-02-24. Last modified 2026-06-17.