1.39.3
2 years ago
5 months ago
Known vulnerabilities in the materialx package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Denial of Service (DoS). An attacker can cause the application to crash or become unresponsive by supplying a deeply nested chain of imported files, leading to stack exhaustion during parsing. Note: This is only exploitable if the attacker can control or supply a crafted file with a recursive import chain. How to fix Denial of Service (DoS)? Upgrade | [1.39.2,1.39.3) |
Affected versions of this package are vulnerable to Stack-based Buffer Overflow via the XML parsing process. An attacker can cause a crash by providing a specially crafted MTLX file with deeply nested How to fix Stack-based Buffer Overflow? Upgrade | [1.39.2,1.39.3) |
Affected versions of this package are vulnerable to NULL Pointer Dereference in the How to fix NULL Pointer Dereference? Upgrade | [1.39.2,1.39.3) |
Affected versions of this package are vulnerable to NULL Pointer Dereference via the How to fix NULL Pointer Dereference? Upgrade | [,1.39.3) |