Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in m3dsafestr (called from m3d_load and Assimp::M3DWrapper::M3DWrapper).
{ "availability": "No subscription required", "binaries": [ { "binary_name": "assimp-testmodels", "binary_version": "5.2.2~ds0-1" }, { "binary_name": "assimp-utils", "binary_version": "5.2.2~ds0-1" }, { "binary_name": "assimp-utils-dbgsym", "binary_version": "5.2.2~ds0-1" }, { "binary_name": "libassimp-dev", "binary_version": "5.2.2~ds0-1" }, { "binary_name": "libassimp-doc", "binary_version": "5.2.2~ds0-1" }, { "binary_name": "libassimp5", "binary_version": "5.2.2~ds0-1" }, { "binary_name": "libassimp5-dbgsym", "binary_version": "5.2.2~ds0-1" }, { "binary_name": "python3-pyassimp", "binary_version": "5.2.2~ds0-1" } ] }