vkoskiv c-ray 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the parse_mtllib function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://github.com/vkoskiv/c-ray/issues/119 | exploit patch |
https://gist.github.com/QiuYitai/6ebfa07510828a9464ba7fb948255ed5 | exploit third party advisory |