Upstream information
Description
Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3d model file that triggers a long error message, as demonstrated by a .ase file.NVD CVSS v2 Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entry: 787305 SUSE Security Advisories:- openSUSE-SU-2012:1506-1, published Tue, 20 Nov 2012 11:08:34 +0100 (CET)
- openSUSE-SU-2013:0146-1, published Wed, 23 Jan 2013 14:05:38 +0100 (CET)
