PT-2025-10589 · Assimp+2 · Assimp+2
Chen Lihai
+1
·
Published
2025-03-10
·
Updated
2026-01-16
·
CVE-2025-2152
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Open Asset Import Library Assimp version 5.4.3
Description
A critical issue has been found in the Open Asset Import Library Assimp, affecting the function
Assimp::BaseImporter::ConvertToUTF8 of the file BaseImporter.cpp in the File Handler component. This issue leads to a heap-based buffer overflow and can be initiated remotely.Recommendations
For Open Asset Import Library Assimp version 5.4.3, as a temporary workaround, consider disabling the
Assimp::BaseImporter::ConvertToUTF8 function until a patch is available. Restrict access to the File Handler component to minimize the risk of exploitation.Exploit
Fix
Memory Corruption
Heap Based Buffer Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Assimp
Debian
Red Os