PT-2025-13834 · Assimp+2 · Assimp+2

·

CVE-2025-3016

·

Published

2025-03-31

·

Updated

2026-06-12

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Open Asset Import Library Assimp version 5.4.3
Description A problematic vulnerability was found in the Open Asset Import Library Assimp. This issue affects the function Assimp::MDLImporter::ParseTextureColorData of the MDL File Handler component. The manipulation of the arguments mWidth and mHeight leads to resource consumption. The attack can be initiated remotely.
Recommendations For Open Asset Import Library Assimp version 5.4.3, upgrade to version 6.0 to address this issue. As a temporary workaround, consider restricting the use of the Assimp::MDLImporter::ParseTextureColorData function until the patch is applied.

Exploit

Fix

DoS

Resource Exhaustion

Improper Resource Release

Buffer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2025-12926
BDU:2025-12927
CVE-2025-3016
OESA-2025-1402
OESA-2025-1403
OESA-2025-1404
OESA-2025-1405
OESA-2026-2645
OPENSUSE-SU-2025:0113-1
OPENSUSE-SU-2025:14950-1
PYSEC-2025-262

Affected Products

Assimp
Debian
Red Os