An improper array index validation vulnerability exists in the LoadObj functionality of tinyobjloader v2.0-rc1 and tinyobjloader development commit 79d4421. A specially crafted file could lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
{
"binaries": [
{
"binary_version": "2.0.0~rc10+dfsg-3build2",
"binary_name": "libtinyobjloader-dev"
},
{
"binary_version": "2.0.0~rc10+dfsg-3build2",
"binary_name": "libtinyobjloader2rc10"
},
{
"binary_version": "2.0.0~rc10+dfsg-3build2",
"binary_name": "python3-tinyobjloader"
}
]
}
{
"binaries": [
{
"binary_version": "2.0.0~rc13+dfsg-2build1",
"binary_name": "libtinyobjloader-dev"
},
{
"binary_version": "2.0.0~rc13+dfsg-2build1",
"binary_name": "libtinyobjloader2rc13"
},
{
"binary_version": "2.0.0~rc13+dfsg-2build1",
"binary_name": "python3-tinyobjloader"
}
]
}