Source: assimp Version: 6.0.5+ds-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for assimp. CVE-2026-19967[0]: | A security flaw has been discovered in Open Asset Import Library | Assimp 17c12da. Impacted is the function | Assimp::Compression::decompressBlock of the file | code/Common/Compression.cpp of the component File Parser. Performing | a manipulation results in heap-based buffer overflow. The attack may | be initiated remotely. The exploit has been released to the public | and may be used for attacks. The project was informed of the problem | early through an issue report but has not responded yet. CVE-2026-19968[1]: | A weakness has been identified in Open Asset Import Library Assimp | 17c12da. The affected element is the function | Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library | code/AssetLib/LWO/LWOLoader.h of the component 3DGS MDL7 Model | Parser. Executing a manipulation can lead to heap-based buffer | overflow. The attack may be launched remotely. The exploit has been | made available to the public and could be used for attacks. This | patch is called ee77bb09a42a49843ac85ef64c14d2328b251df1. Applying a | patch is advised to resolve this issue. CVE-2026-19969[2]: | A security vulnerability has been detected in Open Asset Import | Library Assimp 17c12da. The impacted element is the function | Assimp::MDLImporter::GenerateOutputMeshes_3DGS_MDL7 of the file | code/AssetLib/MDL/MDLLoader.cpp of the component 3DGS MDL7 Model | Output Mesh Generator. The manipulation leads to buffer overflow. | Remote exploitation of the attack is possible. The exploit has been | disclosed publicly and may be used. The project was informed of the | problem early through an issue report but has not responded yet. CVE-2026-19970[3]: | A vulnerability was detected in Open Asset Import Library Assimp | 17c12da. This affects the function | Assimp::MDLImporter::AddBonesToNodeGraph_3DGS_MDL7 of the file | code/AssetLib/MDL/MDLLoader.cpp of the component Node Parser. The | manipulation of the argument bones_num results in heap-based buffer | overflow. The attack can be executed remotely. The exploit is now | public and may be used. The project was informed of the problem | early through an issue report but has not responded yet. CVE-2026-19999[4]: | A security vulnerability has been detected in Open Asset Import | Library Assimp Assimp 17c12da. The affected element is the function | Assimp::MDLImporter::ParseBoneTrafoKeys_3DGS_MDL7 of the file | code/AssetLib/MDL/MDLLoader.cpp of the component 3DGS MDL7 Bone | Transformation Key Parser. The manipulation of the argument | transmatrix_count/pcBoneTransforms leads to buffer overflow. It is | possible to initiate the attack remotely. The exploit has been | disclosed publicly and may be used. The identifier of the patch is | 50d767984e78d51b53e2020fdf0967fd624bc377. It is recommended to apply | a patch to fix this issue. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-19967 https://www.cve.org/CVERecord?id=CVE-2026-19967 [1] https://security-tracker.debian.org/tracker/CVE-2026-19968 https://www.cve.org/CVERecord?id=CVE-2026-19968 [2] https://security-tracker.debian.org/tracker/CVE-2026-19969 https://www.cve.org/CVERecord?id=CVE-2026-19969 [3] https://security-tracker.debian.org/tracker/CVE-2026-19970 https://www.cve.org/CVERecord?id=CVE-2026-19970 [4] https://security-tracker.debian.org/tracker/CVE-2026-19999 https://www.cve.org/CVERecord?id=CVE-2026-19999 Regards, Salvatore

