{"id":"CVE-2024-40724","details":"Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary code by inputting a specially crafted file into the product.","modified":"2026-08-12T15:15:24.325787Z","published":"2024-07-19T07:38:28.057Z","related":["SUSE-SU-2024:2975-1","SUSE-SU-2024:2976-1","SUSE-SU-2024:2984-1","SUSE-SU-2024:2985-1","SUSE-SU-2024:3078-1","SUSE-SU-2024:3079-1","openSUSE-SU-2024:0225-1","openSUSE-SU-2024:14329-1"],"database_specific":{"cna_assigner":"jpcert","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/40xxx/CVE-2024-40724.json"},"references":[{"type":"WEB","url":"https://github.com/assimp/assimp/pull/5651/commits/614911bb3b1bfc3a1799ae2b3cca306270f3fb97"},{"type":"WEB","url":"https://github.com/assimp/assimp/releases/tag/v5.4.2"},{"type":"WEB","url":"https://jvn.jp/en/jp/JVN87710540/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/40xxx/CVE-2024-40724.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-40724"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/assimp/assimp","events":[{"introduced":"ddb74c2bbdee1565dda667e85f0c82a0588c8053"},{"fixed":"ddb74c2bbdee1565dda667e85f0c82a0588c8053"}],"database_specific":{"cpe":"cpe:2.3:a:assimp:assimp:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"prior to 5.4.2"},{"last_affected":"prior to 5.4.2"},{"introduced":"0"},{"fixed":"5.4.2"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"]}}],"versions":["prior to 5.4.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-40724.json","vanir_signatures_modified":"2026-08-12T15:15:24Z","vanir_signatures":[{"digest":{"line_hashes":["291455476283361835711511609575513978478","313169514497802252346797700359228820491","45870465378493471748097096517231672446","30820415993483754259931634674032409248"],"threshold":0.9},"id":"CVE-2024-40724-4525ea76","signature_type":"Line","signature_version":"v1","source":"https://github.com/assimp/assimp/commit/ddb74c2bbdee1565dda667e85f0c82a0588c8053","target":{"file":"code/AssetLib/Ply/PlyLoader.cpp"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"71638971452699370389194316642882257001","length":4436},"id":"CVE-2024-40724-ca0d9a45","signature_type":"Function","signature_version":"v1","source":"https://github.com/assimp/assimp/commit/ddb74c2bbdee1565dda667e85f0c82a0588c8053","target":{"file":"code/AssetLib/Ply/PlyLoader.cpp","function":"PLYImporter::LoadFace"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}