CVE-2025-11277

Name
CVE-2025-11277
Description
A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be exploited.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
issue-tracking https://github.com/assimp/assimp/issues/6358
exploit https://github.com/user-attachments/files/22422643/poc.zip
signature https://vuldb.com/?ctiid.327011
vdb-entry https://vuldb.com/?id.327011
third-party-advisory https://vuldb.com/?submit.658912

Match rules

CPE URI Source package Min version Max version
assimp == 6.0.2 == 6.0.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
assimp edge-community 6.0.2-r0 Russ Webber <russ@rw.id.au> possibly vulnerable
assimp 3.23-community 6.0.2-r0 Russ Webber <russ@rw.id.au> possibly vulnerable