CVE Details
Basic Information
| Title | Open Asset Import Library Assimp HL1MDLLoader.cpp read_meshes heap-based overflow |
|---|---|
| Type | cve |
| Published | 2025-06-16T11:31:06.030Z |
| Last Seen |
Product Information
| Vendor | Open Asset Import Library |
|---|---|
| Product | Assimp |
| Version | 5.4.0 |
CVSS Information
| Base Score | 4.8 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A heap-based buffer overflow vulnerability in the read_meshes function of Open Asset Import Library Assimp up to version 5.4.3. This can cause a crash or potentially allow code execution via a specially crafted file. The issue is exploitable locally. |
|---|---|
| AI Severity | Medium |
| Vendor | Open Asset Import Library |
| Product | Assimp |
| Affected Version | 5.4.0, 5.4.1, 5.4.2, 5.4.3 |
Affected Products
- Open Asset Import Library Assimp 5.4.0
- Open Asset Import Library Assimp 5.4.1
- Open Asset Import Library Assimp 5.4.2
- Open Asset Import Library Assimp 5.4.3
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-122, CWE-119 |
| Bulletin Family |
References
Description
A vulnerability classified as critical was found in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerability is the function read_meshes in the library assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.