PT-2025-39635 · Unknown+1 · Ogrecave Ogre+1

Sand

·

Published

2025-09-26

·

Updated

2025-10-16

·

CVE-2025-11014

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OGRECave Ogre versions up to 14.4.1
Description A security flaw exists in OGRECave Ogre, potentially leading to a heap-based buffer overflow. The issue is located within the STBIImageCodec::encode function in the /ogre/PlugIns/STBICodec/src/OgreSTBICodec.cpp file of the Image Handler component. Exploitation requires local access. The exploit has been publicly released.
Recommendations Versions prior to 14.4.1 should be updated. As a temporary workaround, consider restricting access to the vulnerable file /ogre/PlugIns/STBICodec/src/OgreSTBICodec.cpp to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-11014

Affected Products

Debian
Ogrecave Ogre