Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3d model file that triggers a long error message, as demonstrated by a .ase file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade plib | Jul 30, 2024 | Nov 18, 2012 |
| Freebsd | — | Upgrade plib | Dec 10, 2025 | May 19, 2013 |
| Gentoo Linux | — | Upgrade media-libs/plib. | Mar 27, 2018 | Nov 18, 2012 |
| Suse | — | Upgrade plibUpgrade plib-develUpgrade plib-debuginfoUpgrade plib-debugsource | Feb 17, 2015 | Nov 18, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub