A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument src.entries leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
History

Thu, 17 Jul 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Assimp
Assimp assimp
CPEs cpe:2.3:a:assimp:assimp:5.4.3:*:*:*:*:*:*:*
Vendors & Products Assimp
Assimp assimp

Mon, 31 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Mar 2025 09:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument src.entries leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Title Open Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection out-of-bounds
Weaknesses CWE-119
CWE-125
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-03-25T09:00:10.018Z

Updated: 2025-03-31T16:30:11.979Z

Reserved: 2025-03-24T16:47:31.743Z

Link: CVE-2025-2755

cve-icon Vulnrichment

Updated: 2025-03-31T16:30:05.601Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-25T09:15:17.983

Modified: 2025-07-17T21:48:46.017

Link: CVE-2025-2755

cve-icon Redhat

No data.