PT-2025-13834 · Assimp+2 · Assimp+2

D3Ng03

·

Published

2025-03-31

·

Updated

2025-11-24

·

CVE-2025-3016

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Open Asset Import Library Assimp version 5.4.3
Description A problematic vulnerability was found in the Open Asset Import Library Assimp. This issue affects the function Assimp::MDLImporter::ParseTextureColorData of the MDL File Handler component. The manipulation of the arguments mWidth and mHeight leads to resource consumption. The attack can be initiated remotely.
Recommendations For Open Asset Import Library Assimp version 5.4.3, upgrade to version 6.0 to address this issue. As a temporary workaround, consider restricting the use of the Assimp::MDLImporter::ParseTextureColorData function until the patch is applied.

Exploit

Fix

DoS

Buffer Overflow

Resource Exhaustion

Out of bounds Read

Improper Resource Release

Related Identifiers

BDU:2025-12926
BDU:2025-12927
CVE-2025-3016
OESA-2025-1402
OESA-2025-1403
OESA-2025-1404
OESA-2025-1405
OPENSUSE-SU-2025:0113-1
OPENSUSE-SU-2025:14950-1

Affected Products

Assimp
Debian
Red Os