CVE-2025-2756

Name
CVE-2025-2756
Description
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument tmp leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
issue-tracking https://github.com/assimp/assimp/issues/6018
exploit https://github.com/assimp/assimp/issues/6018#issue-2877375815
signature https://vuldb.com/?ctiid.300861
vdb-entry https://vuldb.com/?id.300861
third-party-advisory https://vuldb.com/?submit.517790

Match rules

CPE URI Source package Min version Max version
assimp == 5.4.3 == 5.4.3
cpe:2.3:a:assimp:assimp:5.4.3:*:*:*:*:*:*:* assimp == None == 5.4.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
assimp edge-community 5.4.3-r0 Russ Webber <russ@rw.id.au> possibly vulnerable
assimp 3.22-community 5.4.3-r0 Russ Webber <russ@rw.id.au> possibly vulnerable