CVE-2024-48424
published 2024-10-24CVE-2024-48424: A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.9th percentile
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| assimp | assimp | — | — |
| assimp | assimp | >= 0 < 6.0.2+ds-1 | 6.0.2+ds-1 |
| debian | assimp | < assimp 6.0.2+ds-1 (forky) | assimp 6.0.2+ds-1 (forky) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
assimp: heap-buffer-overflow in OpenDDLParser::parseStructure
vendor_redhat·2024-10-24·CVSS 5.5
CVE-2024-48424 [MEDIUM] CWE-122 assimp: heap-buffer-overflow in OpenDDLParser::parseStructure
assimp: heap-buffer-overflow in OpenDDLParser::parseStructure
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.
A flaw was found in the Assimp asset import library. An attacker my be able to trigger a buffer overflow condition via specially-crafted OpenGEX files. This may lead to a denial of service or other unexpected behavior.
Statement: The heap-buffer-overflow vulnerability in the Assimp library is classified as moderate because, while it can cause memory corruption or application crashes, it does not inherently lead to arbitrary code execution or privilege escalation. Exploitation requires a crafted OpenGEX file, limiting the attack surface to scenari
Debian
CVE-2024-48424: assimp - A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::p...
vendor_debian·2024·CVSS 5.5
CVE-2024-48424 [MEDIUM] CVE-2024-48424: assimp - A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::p...
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 6.0.2+ds-1)
sid: resolved (fixed in 6.0.2+ds-1)
trixie: open
GHSA
GHSA-93cm-9ghm-5q5v: A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during
ghsa_unreviewed·2024-10-24
CVE-2024-48424 [MEDIUM] CWE-120 GHSA-93cm-9ghm-5q5v: A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.
OSV
CVE-2024-48424: A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during
osv·2024-10-24·CVSS 5.5
CVE-2024-48424 [MEDIUM] CVE-2024-48424: A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.
No detection rules found.
No public exploits indexed.
2024-10-24
Published