Source: assimp Version: 6.0.5+ds-1 Severity: important Tags: security upstream Forwarded: https://github.com/assimp/assimp/pull/6718 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for assimp. CVE-2026-82591[0]: | A security vulnerability has been detected in Open Asset Import | Library Assimp up to 6.0.2. The impacted element is the function | MD5Importer::MakeDataUnique of the file | code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the argument | iNewIndex leads to heap-based buffer overflow. The attack can only | be performed from a local environment. The identifier of the patch | is bf9dabb617c46e5133dac65cca6bff177917afcb. Applying a patch is the | recommended action to fix this issue. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-82591 https://www.cve.org/CVERecord?id=CVE-2026-82591 [1] https://github.com/assimp/assimp/pull/6718 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

