Files
assimp/code/AssetLib
Vinz Spring 5be336779d Fixes CVE-2025-2757: Heap-based Buffer Overflow in AI_MD5_PARSE_STRING_IN_QUOTATION (closes #6019) (#6223)
description:
- heap buffer overflow in AI_MD5_PARSE_STRING_IN_QUOTATION. An attacker could potentially exploit the vulnerability to cause a remote code execution,
  if they can trick the victim into running assimp on a malformed MD5 file

fix:
- truncated the string to the maximum supported length, mitigating overflow

Co-authored-by: Vinz Spring <vinzs@amazon.de>
Co-authored-by: Kim Kulling <kimkulling@users.noreply.github.com>
2025-06-08 13:38:05 +02:00
..
2025-05-03 11:46:10 +02:00
2025-03-27 15:08:21 +01:00
2025-03-27 15:08:21 +01:00
2025-03-26 00:12:55 +01:00
2025-05-07 23:40:53 +02:00
2025-03-26 00:12:55 +01:00
2025-03-27 11:13:44 +01:00
2025-03-26 00:12:55 +01:00
2025-03-26 00:12:55 +01:00
2025-03-27 11:13:44 +01:00
2025-03-27 11:13:44 +01:00
2025-03-27 15:08:21 +01:00
2025-03-27 11:13:44 +01:00
2023-11-12 21:09:33 +01:00
2025-03-27 11:13:44 +01:00
2025-03-27 15:08:21 +01:00
2025-03-27 15:08:21 +01:00
2025-03-05 21:37:47 +01:00
2025-03-27 15:08:21 +01:00
2025-04-27 21:27:45 +02:00
2025-03-27 11:13:44 +01:00
2025-03-05 21:37:47 +01:00
2025-03-26 00:12:55 +01:00
2025-03-05 21:37:47 +01:00
2025-03-05 21:37:47 +01:00
2025-03-26 00:12:55 +01:00
2025-03-26 00:12:55 +01:00
2025-03-26 00:12:55 +01:00
2025-03-05 21:37:47 +01:00
2025-03-26 00:12:55 +01:00
2025-03-26 00:12:55 +01:00
2025-03-26 00:12:55 +01:00
2025-03-26 00:12:55 +01:00
2025-03-26 00:12:55 +01:00
2025-05-16 14:18:37 +02:00
2025-03-27 15:08:21 +01:00
2025-03-26 00:12:55 +01:00
2025-03-27 15:08:21 +01:00
2025-03-27 15:08:21 +01:00
2025-03-26 00:12:55 +01:00