PT-2025-12791 · Assimp+1 · Assimp+1
D3Ng03
·
Published
2025-03-25
·
Updated
2026-04-25
·
CVE-2025-2756
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Open Asset Import Library Assimp version 5.4.3
Description
A critical issue has been found in the Open Asset Import Library Assimp. This issue affects the
Assimp::AC3DImporter::ConvertObjectSection function in the AC3D File Handler component, specifically in the file code/AssetLib/AC/ACLoader.cpp. The manipulation of the tmp argument leads to a heap-based buffer overflow. It is possible to initiate the attack remotely.Recommendations
For Open Asset Import Library Assimp version 5.4.3, as a temporary workaround, consider disabling the
Assimp::AC3DImporter::ConvertObjectSection function until a patch is available. Restrict access to the AC3D File Handler component to minimize the risk of exploitation. Avoid using the tmp argument in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Heap Based Buffer Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Assimp
Debian