CVE-2024-48425
24.10.2024, 21:15
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference.
| Vendor | Product | Version |
|---|---|---|
| assimp | assimp | 5.4.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| assimp |
| ||||||||||||||||
| qt6-3d |
| ||||||||||||||||
| qt6-quick3d |
| ||||||||||||||||
| spring |
|