CVE-2024-48425

Name
CVE-2024-48425
Description
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://github.com/assimp/assimp/issues/5791

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:assimp:assimp:*:*:*:*:*:*:*:* assimp >= 0 <= 5.4.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
assimp edge-community 5.4.3-r0 Russ Webber <russ@rw.id.au> possibly vulnerable
assimp 3.20-community 5.4.3-r0 Russ Webber <russ@rw.id.au> possibly vulnerable