PT-2026-45277 · Debian+2 · Assimp
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Assimp versions prior to 6.0.5
Description
An out-of-bounds read occurs in the Half-Life 1 MDL Loader component within the
HL1MDLLoader::read sequence infos() function of the HL1MDLLoader.cpp file. This issue is triggered by the manipulation of the aiString argument and requires local access to be exploited.Recommendations
Update to version 6.0.5 or later.
As a temporary workaround, restrict the use of the
HL1MDLLoader::read sequence infos() function.Exploit
Fix
Buffer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Assimp