PT-2025-12792 · Assimp+1 · Assimp+1

D3Ng03

·

Published

2025-03-25

·

Updated

2025-07-03

·

CVE-2025-2757

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open Asset Import Library Assimp version 5.4.3
Description A critical vulnerability was found in Open Asset Import Library Assimp, affecting the function AI MD5 PARSE STRING IN QUOTATION of the file code/AssetLib/MD5/MD5Parser.cpp of the component MD5 File Handler. The manipulation of the argument data leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For Open Asset Import Library Assimp version 5.4.3, consider disabling the AI MD5 PARSE STRING IN QUOTATION function until a patch is available. Restrict access to the MD5 File Handler component to minimize the risk of exploitation. Avoid using the affected function in the code/AssetLib/MD5/MD5Parser.cpp file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2757
OPENSUSE-SU-2025:15209-1
PYSEC-2025-168

Affected Products

Assimp
Debian