CVE-2025-3159
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3.
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component ASE File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is e8a6286542924e628e02749c4f5ac4f91fdae71b. It is recommended to apply a patch to fix this issue.
- CVSS 4.0
- 4.8 MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-122
- Affected
- assimp/assimp
- Source
- cna@vuldb.com
References
- https://github.com/assimp/assimp/issues/6024Exploit, Issue Tracking
- https://github.com/assimp/assimp/issues/6024#issue-2877382033Exploit, Issue Tracking
- https://github.com/assimp/assimp/pull/6051Issue Tracking, Patch
- https://github.com/tellypresence/assimp/commit/e8a6286542924e628e02749c4f5ac4f91fdae71bPatch
- https://vuldb.com/?ctiid.303105Permissions Required, VDB Entry
- https://vuldb.com/?id.303105Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.542247Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.