PT-2025-12791 · Assimp+1 · Assimp+1

D3Ng03

·

Published

2025-03-25

·

Updated

2026-04-25

·

CVE-2025-2756

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open Asset Import Library Assimp version 5.4.3
Description A critical issue has been found in the Open Asset Import Library Assimp. This issue affects the Assimp::AC3DImporter::ConvertObjectSection function in the AC3D File Handler component, specifically in the file code/AssetLib/AC/ACLoader.cpp. The manipulation of the tmp argument leads to a heap-based buffer overflow. It is possible to initiate the attack remotely.
Recommendations For Open Asset Import Library Assimp version 5.4.3, as a temporary workaround, consider disabling the Assimp::AC3DImporter::ConvertObjectSection function until a patch is available. Restrict access to the AC3D File Handler component to minimize the risk of exploitation. Avoid using the tmp argument in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2756
OESA-2026-1330
OESA-2026-1331
OESA-2026-1658
OESA-2026-1659
OESA-2026-2057
OPENSUSE-SU-2026:10174-1
PYSEC-2025-167

Affected Products

Assimp
Debian