Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r3jc-f37h-j289

Опубликовано: 04 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation

EPSS

Процентиль: 26%
0.0034
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation

CVSS3: 5.6
redhat
3 месяца назад

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation

CVSS3: 9.8
nvd
3 месяца назад

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation

CVSS3: 9.8
debian
3 месяца назад

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in ...

CVSS3: 9.8
redos
около 1 месяца назад

Уязвимость assimp

EPSS

Процентиль: 26%
0.0034
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-122