Heap-based buffer overflow in assimp - CVE-2024-45679
Published: October 15, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in PlyLoader.cpp. A remote attacker can trick the victim to open a specially crafted file, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
openEuler
assimp-debuginfo
python3-assimp
assimp-help
assimp-devel
assimp-debugsource
assimp
How to mitigate CVE-2024-45679
assimp-debuginfo - addressed in versions 5.2.4-3, 5.3.1-4
python3-assimp - addressed in versions 5.2.4-3, 5.3.1-4
assimp-help - addressed in versions 5.2.4-3, 5.3.1-4
assimp-devel - addressed in versions 5.2.4-3, 5.3.1-4
assimp-debugsource - addressed in versions 5.2.4-3, 5.3.1-4
assimp - addressed in versions 5.2.4-3, 5.3.1-4