PT-2025-16200 · Assimp+2 · Assimp+2

Chen Lihai

+1

·

Published

2025-01-01

·

Updated

2026-02-06

·

CVE-2025-3548

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Open Asset Import Library Assimp versions up to 5.4.3
Description: A critical issue has been found in the Open Asset Import Library Assimp, affecting the function aiString::Set in the library include/assimp/types.h of the component File Handler. This issue leads to a heap-based buffer overflow. The attack can be launched on the local host.
Recommendations: For versions up to 5.4.3, apply a patch to fix this issue. As a temporary workaround, consider restricting the use of the aiString::Set function in the File Handler component until a patch is available.

Exploit

Fix

DoS

Buffer Overflow

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-07019
CVE-2025-3548
OESA-2026-1328
OESA-2026-1329
OESA-2026-1330
OESA-2026-1331
OPENSUSE-SU-2025:15209-1
OPENSUSE-SU-2026:20781-1
SUSE-SU-2026:21821-1

Affected Products

Assimp
Debian
Red Os