Security Advisory

CVE-2020-28589

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-08-11 12:37:20
Last updated 2024-08-04 16:40:59
Assigner talos
State PUBLISHED

Description

An improper array index validation vulnerability exists in the LoadObj functionality of tinyobjloader v2.0-rc1 and tinyobjloader development commit 79d4421. A specially crafted file could lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.