CVE-2025-5169

Name
CVE-2025-5169
Description
A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::InternReadFile_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
issue-tracking https://github.com/assimp/assimp/issues/6128
issue-tracking https://github.com/assimp/assimp/issues/6171
exploit https://github.com/user-attachments/files/20208891/reproducer.zip
signature https://vuldb.com/?ctiid.310257
vdb-entry https://vuldb.com/?id.310257
third-party-advisory https://vuldb.com/?submit.578004

Match rules

CPE URI Source package Min version Max version
assimp == 5.4.3 == 5.4.3
cpe:2.3:a:assimp:assimp:5.4.3:*:*:*:*:*:*:* assimp == None == 5.4.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
assimp edge-community 5.4.3-r0 Russ Webber <russ@rw.id.au> possibly vulnerable
assimp 3.22-community 5.4.3-r0 Russ Webber <russ@rw.id.au> possibly vulnerable