Open Asset Import Library Assimp HL1MDLLoader.cpp read_meshes heap-based overflow

CVE Details

Basic Information

Title Open Asset Import Library Assimp HL1MDLLoader.cpp read_meshes heap-based overflow
Type cve
Published 2025-06-16T11:31:06.030Z
Last Seen

Product Information

Vendor Open Asset Import Library
Product Assimp
Version 5.4.0

CVSS Information

Base Score 4.8 (MEDIUM)
Attack Vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A heap-based buffer overflow vulnerability in the read_meshes function of Open Asset Import Library Assimp up to version 5.4.3. This can cause a crash or potentially allow code execution via a specially crafted file. The issue is exploitable locally.
AI Severity Medium
Vendor Open Asset Import Library
Product Assimp
Affected Version 5.4.0, 5.4.1, 5.4.2, 5.4.3

Affected Products

  • Open Asset Import Library Assimp 5.4.0
  • Open Asset Import Library Assimp 5.4.1
  • Open Asset Import Library Assimp 5.4.2
  • Open Asset Import Library Assimp 5.4.3

Additional Information

CVE List
CWE List CWE-122, CWE-119
Bulletin Family

Description

A vulnerability classified as critical was found in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerability is the function read_meshes in the library assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.