PT-2025-22933 · Assimp+2 · Assimp+2

Clesmian

·

Published

2025-05-26

·

Updated

2026-04-25

·

CVE-2025-5203

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open Asset Import Library Assimp version 5.4.3
Description A vulnerability was found in the Open Asset Import Library Assimp. It has been rated as problematic and affects the SkipSpaces function in the library assimp/include/assimp/ParsingUtils.h. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
Recommendations For Open Asset Import Library Assimp version 5.4.3, as a temporary workaround, consider disabling the SkipSpaces function until a patch is available. Restrict access to the assimp/include/assimp/ParsingUtils.h library to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10063
CVE-2025-5203
OESA-2026-1543
OESA-2026-1658
OESA-2026-1659
OESA-2026-1969
OESA-2026-2055
OESA-2026-2056

Affected Products

Alt Linux
Assimp
Debian