PT-2025-40782 · Assimp+1 · Assimp+1
Sand
·
Published
2025-10-05
·
Updated
2025-10-08
·
CVE-2025-11274
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Open Asset Import Library Assimp version 6.0.2
Description
A flaw exists within the Open Asset Import Library Assimp. The issue is related to resource allocation and occurs in the
Q3DImporter::InternReadFile function located in the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. The exploitation of this issue is limited to local execution. The details of the exploit have been publicly disclosed.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Assimp
Debian