Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-45948

Опубликовано: 01 янв. 2022
Источник: debian
EPSS Низкий

Описание

Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in _m3d_safestr (called from m3d_load and Assimp::M3DWrapper::M3DWrapper).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
assimpfixed5.1.1~ds0-1package
assimpnot-affectedbullseyepackage
assimpnot-affectedbusterpackage
assimpnot-affectedstretchpackage

Примечания

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=34416

  • https://github.com/google/oss-fuzz-vulns/blob/main/vulns/assimp/OSV-2021-775.yaml

  • https://github.com/assimp/assimp/pull/4146

  • https://github.com/assimp/assimp/commit/30f17aa2064b86c0096f0ec701b9e8ea9312fef2 (v5.1.0)

  • Introduced by: https://github.com/assimp/assimp/commit/a622e109a0739435e3e2f05bfbedba0e8385282d (v5.1.0.rc1)

EPSS

Процентиль: 43%
0.00209
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 4 лет назад

Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in _m3d_safestr (called from m3d_load and Assimp::M3DWrapper::M3DWrapper).

CVSS3: 5.5
nvd
около 4 лет назад

Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in _m3d_safestr (called from m3d_load and Assimp::M3DWrapper::M3DWrapper).

CVSS3: 5.5
github
около 4 лет назад

Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in _m3d_safestr (called from m3d_load and Assimp::M3DWrapper::M3DWrapper).

EPSS

Процентиль: 43%
0.00209
Низкий