Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When processing GLTF files with invalid scene node references, the application accesses string members of mesh objects that have been previously freed during actor import operations.
{
"binaries": [
{
"binary_name": "libvtk9-dev",
"binary_version": "9.1.0+really9.1.0+dfsg2-3build1"
},
{
"binary_name": "libvtk9-java",
"binary_version": "9.1.0+really9.1.0+dfsg2-3build1"
},
{
"binary_name": "libvtk9-qt-dev",
"binary_version": "9.1.0+really9.1.0+dfsg2-3build1"
},
{
"binary_name": "libvtk9.1",
"binary_version": "9.1.0+really9.1.0+dfsg2-3build1"
},
{
"binary_name": "libvtk9.1-qt",
"binary_version": "9.1.0+really9.1.0+dfsg2-3build1"
},
{
"binary_name": "python3-vtk9",
"binary_version": "9.1.0+really9.1.0+dfsg2-3build1"
},
{
"binary_name": "vtk9",
"binary_version": "9.1.0+really9.1.0+dfsg2-3build1"
},
{
"binary_name": "vtk9-examples",
"binary_version": "9.1.0+really9.1.0+dfsg2-3build1"
}
]
}
{
"binaries": [
{
"binary_name": "libvtk9-dev",
"binary_version": "9.1.0+really9.1.0+dfsg2-7.1build3"
},
{
"binary_name": "libvtk9-java",
"binary_version": "9.1.0+really9.1.0+dfsg2-7.1build3"
},
{
"binary_name": "libvtk9-qt-dev",
"binary_version": "9.1.0+really9.1.0+dfsg2-7.1build3"
},
{
"binary_name": "libvtk9.1t64",
"binary_version": "9.1.0+really9.1.0+dfsg2-7.1build3"
},
{
"binary_name": "libvtk9.1t64-qt",
"binary_version": "9.1.0+really9.1.0+dfsg2-7.1build3"
},
{
"binary_name": "python3-vtk9",
"binary_version": "9.1.0+really9.1.0+dfsg2-7.1build3"
},
{
"binary_name": "vtk9",
"binary_version": "9.1.0+really9.1.0+dfsg2-7.1build3"
},
{
"binary_name": "vtk9-examples",
"binary_version": "9.1.0+really9.1.0+dfsg2-7.1build3"
}
]
}
{
"binaries": [
{
"binary_name": "libvtk9-dev",
"binary_version": "9.3.0+dfsg1-4ubuntu2"
},
{
"binary_name": "libvtk9-java",
"binary_version": "9.3.0+dfsg1-4ubuntu2"
},
{
"binary_name": "libvtk9-qt-dev",
"binary_version": "9.3.0+dfsg1-4ubuntu2"
},
{
"binary_name": "libvtk9.3",
"binary_version": "9.3.0+dfsg1-4ubuntu2"
},
{
"binary_name": "libvtk9.3-qt",
"binary_version": "9.3.0+dfsg1-4ubuntu2"
},
{
"binary_name": "python3-vtk9",
"binary_version": "9.3.0+dfsg1-4ubuntu2"
},
{
"binary_name": "vtk9",
"binary_version": "9.3.0+dfsg1-4ubuntu2"
},
{
"binary_name": "vtk9-examples",
"binary_version": "9.3.0+dfsg1-4ubuntu2"
}
]
}