CVE-2025-5201

Name
CVE-2025-5201
Description
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function LWOImporter::CountVertsAndFacesLWO2 of the file assimp/code/AssetLib/LWO/LWOLoader.cpp. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
issue-tracking https://github.com/assimp/assimp/issues/6128
issue-tracking https://github.com/assimp/assimp/issues/6173
exploit https://github.com/user-attachments/files/20209125/line-832-reproducer.zip
signature https://vuldb.com/?ctiid.310290
vdb-entry https://vuldb.com/?id.310290
third-party-advisory https://vuldb.com/?submit.578006
134c704f-9b21-4f2e-91b3-4a467353bcc0 https://github.com/assimp/assimp/issues/6174

Match rules

CPE URI Source package Min version Max version
assimp == 5.4.3 == 5.4.3
cpe:2.3:a:assimp:assimp:*:*:*:*:*:*:*:* assimp >= None < 5.4.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
assimp edge-community 5.4.3-r0 Russ Webber <russ@rw.id.au> possibly vulnerable
assimp 3.22-community 5.4.3-r0 Russ Webber <russ@rw.id.au> possibly vulnerable