CNNVD-202510-3946 Information

CNNVD ID

CNNVD-202510-3946

CVE-2025-11464

  • CNNVD Published: 2025-10-29

Description (Chinese)

Ashlar-Vellum Cobalt是Ashlar-Vellum公司的一种基于参数的计算机辅助设计和 3D 建模程序。 Ashlar-Vellum Cobalt存在安全漏洞,该漏洞源于解析CO文件时未正确验证用户提供数据的长度,可能导致远程代码执行。

Description (English)

Ashlar-Vellam Cobalt is an argument-based computer-aided design and 3D modelling program for Ashlar-Vellum. There is a security loophole in Ashlar-Vellam Cobalt, which stems from the failure to correctly verify the length of data provided by users when deciphering CO files and may lead to remote code execution.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

Ashlar-Vellum

Published

2025-10-29

Last Modified

2026-02-24

References

https://www.zerodayinitiative.com/advisories/ZDI-25-955/

Share on: