CVE 8.4 HIGH

bullet3 VHACD utility: stack-based buffer overflow in OFF parser (LoadOFF)_CVE-2025-8854

8.4 / 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to execute arbitrary code via a crafted OFF file with an overlong initial token processed by the VHACD test utility or invoked indirectly through PyBullet's vhacd function.

AI Analysis

A stack-based buffer overflow in the LoadOFF function of bullet3's VHACD utility allows remote attackers to execute arbitrary code via maliciously crafted OFF files.

Basic Information

ID CVE-2025-8854
Source CyberArk
Published Aug 11, 2025 at 04:24

Affected Product

Vendor bulletphysics
Product bullet3
Version <= 3.25
Affected Versions bulletphysics bullet3 <= 3.25

CWE Classification

AI Assessment

AI Severity High
Vendor Bullet Physics Community
Product bullet3
Version <= 3.25

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.