The vendor explicitly identifies these products as affected by this CVE.
- qt5-qt3d as a component of Red Hat Enterprise Linux 9
- qt5-qt3d-devel as a component of Red Hat Enterprise Linux 9
- qt5-qt3d-examples as a component of Red Hat Enterprise Linux 9
- qt5-qt3d.src as a component of Red Hat Enterprise Linux 9
- Summary
- A flaw was found in Assimp, a library for importing various 3D model formats. A local attacker could exploit a heap-based buffer overflow vulnerability in the Half-Life 1 MDL Loader component. By manipulating a specific argument, an attacker could cause the application to crash, leading to a denial of service, or potentially execute unauthorized code. This could result in a loss of system availability or compromise of data.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
