PT-2025-10589 · Assimp+2 · Assimp+2

Chen Lihai

+1

·

Published

2025-03-10

·

Updated

2026-01-16

·

CVE-2025-2152

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Open Asset Import Library Assimp version 5.4.3
Description A critical issue has been found in the Open Asset Import Library Assimp, affecting the function Assimp::BaseImporter::ConvertToUTF8 of the file BaseImporter.cpp in the File Handler component. This issue leads to a heap-based buffer overflow and can be initiated remotely.
Recommendations For Open Asset Import Library Assimp version 5.4.3, as a temporary workaround, consider disabling the Assimp::BaseImporter::ConvertToUTF8 function until a patch is available. Restrict access to the File Handler component to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-07007
CVE-2025-2152
OESA-2026-1079
OESA-2026-1080
OESA-2026-1081
OESA-2026-1082
OESA-2026-1083
OESA-2026-1084
OPENSUSE-SU-2025:15198-1
PYSEC-2025-159

Affected Products

Assimp
Debian
Red Os