Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-10230

Опубликовано: 01 июн. 2026
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

A vulnerability was identified in Assimp up to 6.0.4. This impacts the function Assimp::MDL::HalfLife::HL1MDLLoader::read_animations of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The project tagged the reported issue as bug.

A flaw was found in Assimp, specifically within the Half-Life 1 MDL Loader component. A local attacker could exploit a heap-based buffer overflow vulnerability in the read_animations function of HL1MDLLoader.cpp. This could lead to information disclosure, denial of service, or potentially arbitrary code execution.

Отчет

This Moderate-impact flaw in Assimp's Half-Life 1 MDL Loader component allows a local attacker to trigger a heap-based buffer overflow by processing a specially crafted MDL file. While this could lead to information disclosure, denial of service, or arbitrary code execution, the requirement for local access and user interaction limits the overall risk in most Red Hat environments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10qt6-qtquick3dNot affected
Red Hat Enterprise Linux 9qt5-qt3dFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2483759assimp: Assimp: Local heap-based buffer overflow in Half-Life 1 MDL Loader

EPSS

Процентиль: 3%
0.00127
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

A vulnerability was identified in Assimp up to 6.0.4. This impacts the function Assimp::MDL::HalfLife::HL1MDLLoader::read_animations of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The project tagged the reported issue as bug.

CVSS3: 5.3
nvd
3 месяца назад

A vulnerability was identified in Assimp up to 6.0.4. This impacts the function Assimp::MDL::HalfLife::HL1MDLLoader::read_animations of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The project tagged the reported issue as bug.

CVSS3: 5.3
debian
3 месяца назад

A vulnerability was identified in Assimp up to 6.0.4. This impacts the ...

CVSS3: 5.3
github
3 месяца назад

A vulnerability was identified in Assimp up to 6.0.4. This impacts the function Assimp::MDL::HalfLife::HL1MDLLoader::read_animations of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The project tagged the reported issue as bug.

EPSS

Процентиль: 3%
0.00127
Низкий

5.6 Medium

CVSS3