Irrlicht: User-assisted execution of arbitrary code A buffer overflow might lead to the execution of arbitrary code or a Denial of Service. irrlicht 2009-03-07 2009-03-07 252203 remote 1.5 1.5

The Irrlicht Engine is an open source cross-platform high performance realtime 3D engine written in C++.

An unspecified component of the B3D loader is vulnerable to a buffer overflow due to missing boundary checks.

A remote attacker could entice a user to open a specially crafted .irr file, possibly resulting in the execution of arbitrary code with the privileges of the user running the application, or a Denial of Service (crash).

There is no known workaround at this time.

All irrlicht users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-games/irrlicht-1.5"
CVE-2008-5876 rbu a3li a3li