PT-2024-5528 · Assimp+4 · Assimp+4

Yuhei Kawakoya

·

Published

2024-07-19

·

Updated

2025-01-27

·

CVE-2024-40724

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Assimp versions prior to 5.4.2
Description The issue is related to a heap-based buffer overflow vulnerability. It allows a local attacker to execute arbitrary code by inputting a specially crafted file into the product. This can be achieved through the exploitation of the File Handler component in the Open Asset Import Library (Assimp), which is associated with the heap buffer overflow.
Recommendations For versions prior to 5.4.2, update to version 5.4.2 or later to resolve the issue. As a temporary workaround, consider restricting the input of specially crafted files into the product until a patch is available.

Fix

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2024-11343
ALT-PU-2024-11397
BDU:2024-06186
CVE-2024-40724
MGASA-2024-0300
OESA-2024-1910
OESA-2024-1911
OESA-2024-1912
OESA-2024-1913
OPENSUSE-SU-2024:0225-1
OPENSUSE-SU-2024:14329-1
OPENSUSE-SU-2024_2976-1
OPENSUSE-SU-2024_2984-1
OPENSUSE-SU-2024_2985-1
OPENSUSE-SU-2024_3078-1
OPENSUSE-SU-2024_3079-1
ROSA-SA-2025-2588
SUSE-SU-2024:2975-1
SUSE-SU-2024:2976-1
SUSE-SU-2024:2984-1
SUSE-SU-2024:2985-1
SUSE-SU-2024:3078-1
SUSE-SU-2024:3079-1
SUSE-SU-2024_2975-1
SUSE-SU-2024_2976-1
SUSE-SU-2024_2984-1
SUSE-SU-2024_3079-1

Affected Products

Alt Linux
Assimp
Debian
Red Os
Suse