PT-2024-5528 · Assimp+4 · Assimp+4
Yuhei Kawakoya
·
Published
2024-07-19
·
Updated
2025-01-27
·
CVE-2024-40724
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Assimp versions prior to 5.4.2
Description
The issue is related to a heap-based buffer overflow vulnerability. It allows a local attacker to execute arbitrary code by inputting a specially crafted file into the product. This can be achieved through the exploitation of the File Handler component in the Open Asset Import Library (Assimp), which is associated with the heap buffer overflow.
Recommendations
For versions prior to 5.4.2, update to version 5.4.2 or later to resolve the issue.
As a temporary workaround, consider restricting the input of specially crafted files into the product until a patch is available.
Fix
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Assimp
Debian
Red Os
Suse