MGASA-2024-0300 - Updated assimp packages fix security vulnerability

Publication date: 13 Sep 2024
URL: https://advisories.mageia.org/MGASA-2024-0300.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-40724

Heap-based buffer overflow vulnerability in Assimp allows a local
attacker to execute arbitrary code by inputting a specially crafted file
into the program.

References:
- https://bugs.mageia.org/show_bug.cgi?id=33531
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GRHXRZKHWQMKKB7V55J2TDPZAKJSN2BF/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40724

SRPMS:
- 9/core/assimp-5.2.2-4.1.mga9

Mageia 2024-0300: assimp Security Advisory Updates

Heap-based buffer overflow vulnerability in Assimp allows a local attacker to execute arbitrary code by inputting a specially crafted file into the program

Summary

Heap-based buffer overflow vulnerability in Assimp allows a local attacker to execute arbitrary code by inputting a specially crafted file into the program.

References

- https://bugs.mageia.org/show_bug.cgi?id=33531

- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GRHXRZKHWQMKKB7V55J2TDPZAKJSN2BF/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40724

Resolution

MGASA-2024-0300 - Updated assimp packages fix security vulnerability

SRPMS

- 9/core/assimp-5.2.2-4.1.mga9

Severity
Publication date: 13 Sep 2024
URL: https://advisories.mageia.org/MGASA-2024-0300.html
Type: security
CVE: CVE-2024-40724

Related News