Logo
componentogre
Name
ogre
Version
v14.4.1
Type
library
Description
-
Licenses
MIT (main library, DeferredShadingMedia samples)Public Domain (samples and plugins)
PURL
-
CPE
cpe:2.3:a:ogre3d:ogre:14.4.1:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
2025.02.x
v1.12.12

Vulnerabilities#


Name
Analysis
Description
Exploitable
A vulnerability was detected in OGRECave Ogre up to 14.4.1. The impacted element is the function Ogre::LogManager::stream of the file /ogre/OgreMain/src/OgreLogManager.cpp. Performing manipulation of the argument mDefaultLog results in null pointer dereference. The attack must be initiated from a local position. The exploit is now public and may be used.
Exploitable
A security flaw has been discovered in OGRECave Ogre up to 14.4.1. This issue affects the function STBIImageCodec::encode of the file /ogre/PlugIns/STBICodec/src/OgreSTBICodec.cpp of the component Image Handler. The manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been released to the public and may be exploited.