CVE-2025-11275

Name
CVE-2025-11275
Description
A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function ODDLParser::getNextSeparator in the library assimp/contrib/openddlparser/include/openddlparser/OpenDDLParserUtils.h. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
issue-tracking https://github.com/assimp/assimp/issues/6357
exploit https://github.com/user-attachments/files/22417682/poc.zip
signature https://vuldb.com/?ctiid.327009
vdb-entry https://vuldb.com/?id.327009
third-party-advisory https://vuldb.com/?submit.658675

Match rules

CPE URI Source package Min version Max version
assimp == 6.0.2 == 6.0.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
assimp edge-community 6.0.2-r0 Russ Webber <russ@rw.id.au> possibly vulnerable
assimp 3.23-community 6.0.2-r0 Russ Webber <russ@rw.id.au> possibly vulnerable