6.8
CVSSv2

CVE-2012-4552

Published: 18/11/2012 Updated: 26/06/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote malicious users to execute arbitrary code via a crafted 3d model file that triggers a long error message, as demonstrated by a .ase file.

Vulnerable Product Search on Vulmon Subscribe to Product

steve j baker plib 1.8.5

Vendor Advisories

Debian Bug report logs - #694810 plib: CVE-2012-4552 Package: plib; Maintainer for plib is Debian QA Group <packages@qadebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 30 Nov 2012 15:21:02 UTC Severity: grave Tags: patch Found in version 185-5 Fixed in version plib/185-6 Done: Michael S ...

Exploits

/* # Exploit Title: Plib + flightgear 3dconvert exploit # Date: 08/10/2012 # Author: Andres Gomez # Software Links: # Plib: plibsourceforgenet/ # flightgear: wwwflightgearorg/ # 3dconvert: ftp://ftpihguni-duisburgde/FlightGear/Win32/old/3dconvert-win32zip # Version: Plib 185 # Tested on: Windows XP Service Pack 3 Spanish * ...