Описание
A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. Patch name: eb84eec580d3f4ba2f0fd87409b7d0744620f11e. Applying a patch is the recommended action to fix this issue.
A flaw was found in Open Asset Import Library Assimp. This vulnerability, a heap-based buffer overflow, allows a local attacker to manipulate input when processing CSM files. Successful exploitation could lead to information disclosure, compromise of data integrity, or a denial of service (DoS).
Отчет
A heap-based buffer overflow in the Open Asset Import Library (Assimp) allows a local attacker to cause information disclosure and a denial of service by processing a specially crafted CSM file. Exploitability is limited by the requirement for local system access.
Меры по смягчению последствий
Do not process Character Studio Motion (.csm) files from untrusted sources. If CSM support is not required, mitigate the flaw by rebuilding Assimp with the ASSIMP_BUILD_NO_CSM_IMPORTER flag enabled, or by configuring Qt 3D and Qt Quick 3D to block .csm asset imports at the application level.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | qt6-qtquick3d | Fix deferred | ||
| Red Hat Enterprise Linux 9 | qt5-qt3d | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. Patch name: eb84eec580d3f4ba2f0fd87409b7d0744620f11e. Applying a patch is the recommended action to fix this issue.
A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. Patch name: eb84eec580d3f4ba2f0fd87409b7d0744620f11e. Applying a patch is the recommended action to fix this issue.
A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. ...
A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. Patch name: eb84eec580d3f4ba2f0fd87409b7d0744620f11e. Applying a patch is the recommended action to fix this issue.
EPSS
5.3 Medium
CVSS3