A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument tmp leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
History

Thu, 17 Jul 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Assimp
Assimp assimp
CPEs cpe:2.3:a:assimp:assimp:5.4.3:*:*:*:*:*:*:*
Vendors & Products Assimp
Assimp assimp

Mon, 31 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 02:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 25 Mar 2025 09:45:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument tmp leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Title Open Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection heap-based overflow
Weaknesses CWE-119
CWE-122
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-03-25T09:31:04.310Z

Updated: 2025-03-31T16:26:30.042Z

Reserved: 2025-03-24T16:47:34.456Z

Link: CVE-2025-2756

cve-icon Vulnrichment

Updated: 2025-03-31T16:26:25.953Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-25T10:15:16.627

Modified: 2025-07-17T21:47:29.243

Link: CVE-2025-2756

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-03-25T09:31:04Z

Links: CVE-2025-2756 - Bugzilla