Описание
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.
A flaw was found in assimp, an asset import library. A local attacker may be able to use specially-crafted input to trigger a buffer overflow condition. This can lead to an application crash or other unexpected behavior.
Отчет
The vulnerability in Assimp is considered moderate rather than important because it requires local access and specially crafted input files to exploit, limiting its impact and attack surface. While a buffer overflow can indeed cause an application crash or unpredictable behavior, exploitation is not straightforward, as it does not inherently lead to code execution or privilege escalation without additional conditions. Furthermore, the flaw affects only applications that utilize Assimp for processing untrusted or user-supplied 3D models. It's important to note that this vulnerability does not impact any Red Hat products, indicating that Red Hat's software stack is unaffected by this specific CVE.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 9 | qt5-qt3d | Not affected |
Показывать по
Дополнительная информация
Статус:
6.6 Medium
CVSS3
Связанные уязвимости
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrar ...
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.
6.6 Medium
CVSS3