Open Asset Import Library Assimp MDLLoader.cpp InternReadFile_Quake1 out-of-bounds

CVE Details

Basic Information

Title Open Asset Import Library Assimp MDLLoader.cpp InternReadFile_Quake1 out-of-bounds
Type cve
Published 2025-05-26T18:31:06.626Z
Last Seen

Product Information

Vendor Open Asset Import Library
Product Assimp
Version 5.4.3

CVSS Information

Base Score 4.8 (MEDIUM)
Attack Vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A vulnerability in Open Asset Import Library Assimp 5.4.3 allows an attacker to cause an out-of-bounds read via the MDLImporter::InternReadFile_Quake1 function in MDLLoader.cpp. The vulnerability can be exploited locally and has been publicly disclosed. The project is tracking all fuzzer bugs in a main issue for future resolution.
AI Severity Medium
Vendor Open Asset Import Library
Product Assimp
Affected Version 5.4.3

Additional Information

CVE List
CWE List CWE-125, CWE-119
Bulletin Family
Source Data Open Asset Import Library Assimp 5.4.3

Source Information

Source Data Open Asset Import Library Assimp 5.4.3
Source Link

Description

A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDLImporter::InternReadFile_Quake1 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation leads to out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.

CVSS Score Summary

Base Score: 4.8 (MEDIUM)

View Full CVE Details

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.