Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://gitlab.kitware.com/vtk/vtk/-/issues/19732 |
|
History
Mon, 03 Nov 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vtk
Vtk vtk |
|
| Vendors & Products |
Vtk
Vtk vtk |
Fri, 31 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-122 | |
| Metrics |
cvssV3_1
|
Fri, 31 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-10-31T00:00:00.000Z
Updated: 2025-10-31T18:06:36.870Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-57107
Updated: 2025-10-31T18:05:35.940Z
Status : Awaiting Analysis
Published: 2025-10-31T15:15:42.443
Modified: 2025-11-04T15:41:31.450
Link: CVE-2025-57107
No data.
ReportizFlow