Use After Free Vulnerability in Assimp Library Affecting Multiple Versions
CVE-2022-45748

8.8HIGH

Key Information:

Vendor

Assimp

Status
Vendor
CVE Published:
20 January 2023

What is CVE-2022-45748?

A vulnerability exists in the Assimp library (version 5.1.4) where a use after free condition is triggered in the function ColladaParser::ExtractDataObjectFromChannel. This issue arises during the parsing of Collada files, which can potentially lead to unintended access to freed memory, paving the way for security exploits. Developers relying on this library should take immediate action to mitigate any risks associated with the affected version.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.