PT-2025-12420 · Assimp+2 · Assimp+2
D3Ng03
·
Published
2025-03-21
·
Updated
2026-02-13
·
CVE-2025-2592
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Open Asset Import Library Assimp version 5.4.3
Description
A critical vulnerability has been found in Open Asset Import Library Assimp. This issue affects the function
CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.Recommendations
To fix this issue, apply the patch named
2690e354da0c681db000cfd892a55226788f2743. As a temporary workaround, consider disabling the CSMImporter::InternReadFile function until a patch is available. Restrict access to the vulnerable file code/AssetLib/CSM/CSMLoader.cpp to minimize the risk of exploitation.Exploit
Fix
DoS
Divide By Zero
Buffer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Assimp
Debian
Red Os