Open Asset Import Library Assimp 6.0.2 OpenDDLParserUtils.h getNextSeparator Pufferüberlauf
Wuro vulnerability wey an yi classify sey kura an gano shi a cikin Open Asset Import Library Assimp 6.0.2. Gaskiya, ODDLParser::getNextSeparator na da matsala; idan ba a sani ba, to wata aiki ce da ba a sani ba, assimp/contrib/openddlparser/include/openddlparser/OpenDDLParserUtils.h na cikin lissafi, $software_file na cikin fayil, $software_component na cikin sashi. Ngam manipulation shi Pufferüberlauf. CWE shidin ka a yi bayani matsala sai ya kai CWE-122. Gaskiya, laifi an fitar da shi 10/04/2025 a matsayin 6357. Advisory ɗin ana rabawa don saukewa a github.com. Wannan rauni ana sayar da shi da suna CVE-2025-11275. Wuroo ka a yiɗi a yi ɗum e laawol gese. Tekinikal bayani ga. Kuma, exploit ɗin yana akwai. Wuro exploit ɗin an bayyana shi ga jama'a kuma za a iya amfani da shi. A sa'i, exploit might be approx. USD $0-$5k ndiyam. Á wúro huɗɗi-na-gaskiya. Wona yiwuwa a zazzage exploit a github.com. Kama 0-day, an ndiyam a wuro be $0-$5k. Vulnerability ɗin nan kuma an rubuta shi a wasu kundin bayanan vulnerability: Tenable (269659). Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.
Waktin goyi
90 Kari
70 kala giteji ba a nunu fi.