peter bassill · operator
$ cve CVE-2012-4552 JSON

CVE-2012-4552 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 10% (pctl 95)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3d model file that triggers a long error message, as demonstrated by a .ase file.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS9.97% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2012-11-18
Last modified2026-06-16

Affected (1)

VendorProduct
steve j bakerplib

Public exploits

SourceTitleDate
exploit-dbPLIB 1.8.5 - 'ssg/ssgParser.cxx' Local Buffer Overflow2012-10-09

References

→ the Explorer  ·  watch your stack  ·  NVD