PT-2025-12785 · Assimp+1 · Assimp+1

D3Ng03

·

Published

2025-03-25

·

Updated

2026-04-25

·

CVE-2025-2755

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open Asset Import Library Assimp version 5.4.3
Description A critical issue affects the function Assimp::AC3DImporter::ConvertObjectSection of the component AC3D File Handler. The manipulation of the argument src.entries leads to an out-of-bounds read. This issue can be exploited remotely.
Recommendations For Open Asset Import Library Assimp version 5.4.3, as a temporary workaround, consider disabling the Assimp::AC3DImporter::ConvertObjectSection function until a patch is available. Restrict access to the AC3D File Handler component to minimize the risk of exploitation. Avoid using the argument src.entries in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2755
OESA-2026-1543
OESA-2026-1658
OESA-2026-1659
OESA-2026-1969
OESA-2026-2055
OESA-2026-2056
PYSEC-2025-166

Affected Products

Assimp
Debian