Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary code by inputting a specially crafted file into the product.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "5.4.2+ds-1", "binary_name": "assimp-testmodels" }, { "binary_version": "5.4.2+ds-1", "binary_name": "assimp-utils" }, { "binary_version": "5.4.2+ds-1", "binary_name": "assimp-utils-dbgsym" }, { "binary_version": "5.4.2+ds-1", "binary_name": "libassimp-dev" }, { "binary_version": "5.4.2+ds-1", "binary_name": "libassimp-doc" }, { "binary_version": "5.4.2+ds-1", "binary_name": "libassimp5" }, { "binary_version": "5.4.2+ds-1", "binary_name": "libassimp5-dbgsym" }, { "binary_version": "5.4.2+ds-1", "binary_name": "python3-pyassimp" } ] }