CVE-2024-53425
published 2024-11-21CVE-2024-53425: A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed…
PriorityP423medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.30%
21.9th percentile
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| assimp | assimp | — | — |
| assimp | assimp | >= 0 < 6.0.2+ds-1 | 6.0.2+ds-1 |
| debian | assimp | < assimp 6.0.2+ds-1 (forky) | assimp 6.0.2+ds-1 (forky) |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-53vp-hv55-j8x4: A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5
ghsa_unreviewed·2024-11-26
CVE-2024-53425 [MEDIUM] CWE-120 GHSA-53vp-hv55-j8x4: A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash.
OSV
CVE-2024-53425: A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5
osv·2024-11-21·CVSS 6.2
CVE-2024-53425 [MEDIUM] CVE-2024-53425: A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash.
Red Hat
assimp: heap-based buffer overflow in SkipSpacesAndLineEnd
vendor_redhat·2024-11-21·CVSS 6.2
CVE-2024-53425 [MEDIUM] CWE-122 assimp: heap-based buffer overflow in SkipSpacesAndLineEnd
assimp: heap-based buffer overflow in SkipSpacesAndLineEnd
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash.
A heap buffer overflow vulnerability was found in the Assimp package. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash.
Package: qt5-qt3d (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2024-53425: assimp - A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd ...
vendor_debian·2024·CVSS 6.2
CVE-2024-53425 [MEDIUM] CVE-2024-53425: assimp - A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd ...
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 6.0.2+ds-1)
sid: resolved (fixed in 6.0.2+ds-1)
trixie: open
No detection rules found.
No public exploits indexed.
2024-11-21
Published