Bug ID 1194276
Summary VUL-1: CVE-2021-45948: assimp: heap-based buffer overflow in _m3d_safestr
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.3
Hardware Other
URL https://smash.suse.de/issue/319357/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Basesystem
Assignee christophe@krop.fr
Reporter abergmann@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2021-45948

Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer
overflow in _m3d_safestr (called from m3d_load and
Assimp::M3DWrapper::M3DWrapper).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-45948
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=34416
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/assimp/OSV-2021-775.yaml
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45948
http://www.cvedetails.com/cve/CVE-2021-45948/


You are receiving this mail because: