PT-2026-45276 · Assimp · Assimp
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Assimp versions prior to 6.0.5
Description
A use after free issue exists in the ASE File Parser component within the
aiNode::~aiNode() function of the scene.cpp file. This flaw allows a local attacker to execute a manipulation that leads to the use of memory after it has been freed.Recommendations
Update to version 6.0.5 or later.
As a temporary workaround, restrict the use of the ASE File Parser component.
Exploit
Fix
Buffer Overflow
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Assimp