PT-2025-13834 · Assimp+2 · Assimp+2
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Open Asset Import Library Assimp version 5.4.3
Description
A problematic vulnerability was found in the Open Asset Import Library Assimp. This issue affects the function
Assimp::MDLImporter::ParseTextureColorData of the MDL File Handler component. The manipulation of the arguments mWidth and mHeight leads to resource consumption. The attack can be initiated remotely.Recommendations
For Open Asset Import Library Assimp version 5.4.3, upgrade to version 6.0 to address this issue. As a temporary workaround, consider restricting the use of the
Assimp::MDLImporter::ParseTextureColorData function until the patch is applied.Exploit
Fix
DoS
Resource Exhaustion
Improper Resource Release
Buffer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Assimp
Debian
Red Os