PT-2025-39635 · Unknown+1 · Ogrecave Ogre+1

·

CVE-2025-11014

·

Published

2025-09-26

·

Updated

2025-10-16

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OGRECave Ogre versions up to 14.4.1
Description A security flaw exists in OGRECave Ogre, potentially leading to a heap-based buffer overflow. The issue is located within the STBIImageCodec::encode function in the /ogre/PlugIns/STBICodec/src/OgreSTBICodec.cpp file of the Image Handler component. Exploitation requires local access. The exploit has been publicly released.
Recommendations Versions prior to 14.4.1 should be updated. As a temporary workaround, consider restricting access to the vulnerable file /ogre/PlugIns/STBICodec/src/OgreSTBICodec.cpp to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11014

Affected Products

Debian
Ogrecave Ogre