CVE-2024-40724: Buffer Overflow
Published Jul 19, 2024
·Updated
Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary code by inputting a specially crafted file into the product.
Affected Software
1 affected component
Assimp Assimp<5.4.2
Remediation
Event History
Jul 19, 2024
CVE Published
via MITRE·07:38 AM
Data Sourced
via MITRE·07:38 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40724?
CVE-2024-40724 is classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2024-40724?
To fix CVE-2024-40724, upgrade Assimp to version 5.4.2 or later.
3
What versions of Assimp are affected by CVE-2024-40724?
Assimp versions prior to 5.4.2 are affected by CVE-2024-40724.
4
What type of vulnerability is CVE-2024-40724?
CVE-2024-40724 is a heap-based buffer overflow vulnerability.
5
Who can exploit CVE-2024-40724?
A local attacker can exploit CVE-2024-40724 by inputting a specially crafted file.