UBUNTU-CVE-2024-8374

Source
https://ubuntu.com/security/CVE-2024-8374
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-8374.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2024-8374
Related
Published
2024-09-03T10:15:00Z
Modified
2025-01-13T10:24:48Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/plugins/ThreeMFReader.py). The vulnerability arises from improper handling of the droptobuildplate property within 3MF files, which are ZIP archives containing the model data. When a 3MF file is loaded in Cura, the value of the droptobuildplate property is passed to the Python eval() function without proper sanitization, allowing an attacker to execute arbitrary code by crafting a malicious 3MF file. This vulnerability poses a significant risk as 3MF files are commonly shared via 3D model databases.

References

Affected packages

Ubuntu:Pro:18.04:LTS / cura

Package

Name
cura
Purl
pkg:deb/ubuntu/cura@3.1.0-1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.0.3-2
3.1.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / cura

Package

Name
cura
Purl
pkg:deb/ubuntu/cura@4.4.1-1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.3.1-2

4.*

4.4.1-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / cura

Package

Name
cura
Purl
pkg:deb/ubuntu/cura@4.13.0-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.8-4
4.8-4build1
4.8-5
4.13.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}