A security flaw has been discovered in OGRECave Ogre up to 14.4.1. This issue affects the function STBIImageCodec::encode of the file /ogre/PlugIns/STBICodec/src/OgreSTBICodec.cpp of the component Image Handler. The manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been released to the public and may be exploited.
{
"binaries": [
{
"binary_version": "1.12.4+dfsg1-4",
"binary_name": "libogre-1.12"
},
{
"binary_version": "1.12.4+dfsg1-4",
"binary_name": "libogre-1.12-dev"
},
{
"binary_version": "1.12.4+dfsg1-4",
"binary_name": "ogre-1.12-tools"
},
{
"binary_version": "1.12.4+dfsg1-4",
"binary_name": "python3-ogre-1.12"
}
]
}
{
"binaries": [
{
"binary_version": "1.12.10+dfsg2-1.2build1",
"binary_name": "libogre-1.12-dev"
},
{
"binary_version": "1.12.10+dfsg2-1.2build1",
"binary_name": "libogre1.12.10"
},
{
"binary_version": "1.12.10+dfsg2-1.2build1",
"binary_name": "ogre-1.12-tools"
},
{
"binary_version": "1.12.10+dfsg2-1.2build1",
"binary_name": "python3-ogre-1.12"
}
]
}
{
"binaries": [
{
"binary_version": "1.12.10+dfsg2-3.1~exp1ubuntu3",
"binary_name": "libogre-1.12-dev"
},
{
"binary_version": "1.12.10+dfsg2-3.1~exp1ubuntu3",
"binary_name": "libogre1.12.10t64"
},
{
"binary_version": "1.12.10+dfsg2-3.1~exp1ubuntu3",
"binary_name": "ogre-1.12-tools"
},
{
"binary_version": "1.12.10+dfsg2-3.1~exp1ubuntu3",
"binary_name": "python3-ogre-1.12"
}
]
}
{
"binaries": [
{
"binary_version": "1.12.10+dfsg2-6build1",
"binary_name": "libogre-1.12-dev"
},
{
"binary_version": "1.12.10+dfsg2-6build1",
"binary_name": "libogre1.12.10t64"
},
{
"binary_version": "1.12.10+dfsg2-6build1",
"binary_name": "ogre-1.12-tools"
},
{
"binary_version": "1.12.10+dfsg2-6build1",
"binary_name": "python3-ogre-1.12"
}
]
}