CVE-2022-38528: Medium severity assimp vulnerability
Open Asset Import Library (assimp) commit 3c253ca was discovered to contain a segmentation violation via the component Assimp::XFileImporter::CreateMeshes.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38528?
CVE-2022-38528 is a vulnerability found in Open Asset Import Library (assimp) version 5.2.5 that allows a remote attacker to cause a segmentation violation via a specific component.
How severe is CVE-2022-38528?
CVE-2022-38528 has a severity score of 6.5, which is considered medium severity.
Which software versions are affected by CVE-2022-38528?
Open Asset Import Library (assimp) version 5.2.5 is affected by CVE-2022-38528.
How can I fix CVE-2022-38528?
To fix CVE-2022-38528, it is recommended to update to a patched version of Open Asset Import Library (assimp) that addresses the segmentation violation.
Where can I find more information about CVE-2022-38528?
More information about CVE-2022-38528 can be found at the following reference link: [GitHub Issue #4662](https://github.com/assimp/assimp/issues/4662).