CVE-2022-45748
published 2023-01-20CVE-2022-45748: An issue was discovered with assimp 5.1.4, a use after free occurred in function ColladaParser::ExtractDataObjectFromChannel in file…
PriorityP337high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.72%
49.8th percentile
An issue was discovered with assimp 5.1.4, a use after free occurred in function ColladaParser::ExtractDataObjectFromChannel in file /code/AssetLib/Collada/ColladaParser.cpp.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| assimp | assimp | — | — |
| assimp | assimp | >= 0 < 5.3.1+ds-2 | 5.3.1+ds-2 |
| assimp | assimp | >= 0 < 5.3.1+ds-2 | 5.3.1+ds-2 |
| debian | assimp | < assimp 5.3.1+ds-2 (forky) | assimp 5.3.1+ds-2 (forky) |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2f85-6r7v-qrg9: An issue was discovered with assimp 5
ghsa_unreviewed·2023-01-20
CVE-2022-45748 [HIGH] CWE-416 GHSA-2f85-6r7v-qrg9: An issue was discovered with assimp 5
An issue was discovered with assimp 5.1.4, a use after free occurred in function ColladaParser::ExtractDataObjectFromChannel in file /code/AssetLib/Collada/ColladaParser.cpp.
OSV
CVE-2022-45748: An issue was discovered with assimp 5
osv·2023-01-20·CVSS 8.8
CVE-2022-45748 [HIGH] CVE-2022-45748: An issue was discovered with assimp 5
An issue was discovered with assimp 5.1.4, a use after free occurred in function ColladaParser::ExtractDataObjectFromChannel in file /code/AssetLib/Collada/ColladaParser.cpp.
Debian
CVE-2022-45748: assimp - An issue was discovered with assimp 5.1.4, a use after free occurred in function...
vendor_debian·2022·CVSS 8.8
CVE-2022-45748 [HIGH] CVE-2022-45748: assimp - An issue was discovered with assimp 5.1.4, a use after free occurred in function...
An issue was discovered with assimp 5.1.4, a use after free occurred in function ColladaParser::ExtractDataObjectFromChannel in file /code/AssetLib/Collada/ColladaParser.cpp.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 5.3.1+ds-2)
sid: resolved (fixed in 5.3.1+ds-2)
trixie: resolved (fixed in 5.3.1+ds-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-20
Published