Open Asset Import Library Assimp MDLLoader.cpp InternReadFile_3DGS_MDL345 out-of-bounds

CVE Details

Basic Information

Title Open Asset Import Library Assimp MDLLoader.cpp InternReadFile_3DGS_MDL345 out-of-bounds
Type cve
Published 2025-05-26T04:31:06.070Z
Last Seen

Product Information

Vendor Open Asset Import Library
Product Assimp
Version 5.4.3

CVSS Information

Base Score 4.8 (MEDIUM)
Attack Vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description The Open Asset Import Library (Assimp) version 5.4.3 has a vulnerability in its MDL loader, specifically in the function MDLImporter::InternReadFile_3DGS_MDL345. This vulnerability allows an attacker to perform an out-of-bounds read, potentially leading to information disclosure. The vulnerability requires local access to exploit and has been publicly disclosed.
AI Severity Medium
Vendor Open Asset Import Library
Product Assimp
Affected Version 5.4.3

Additional Information

CVE List
CWE List CWE-125, CWE-119
Bulletin Family
Source Data Open Asset Import Library Assimp 5.4.3

Source Information

Source Data Open Asset Import Library Assimp 5.4.3
Source Link

Description

A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::InternReadFile_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.

CVSS Score Summary

Base Score: 4.8 (MEDIUM)

View Full CVE Details

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.