CVE-2025-3549
LOW3.3EPSS 0.08%Published: 4/14/2025Modified: 5/21/2026
Description
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/AssetLib/MD3/MD3Loader.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Affected packages (2)
- Debian/assimpfrom 0
- PyPI/pyassimpfrom 0, <= 5.4.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
References (6)
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2025-3549
- ADVISORYhttps://vuldb.com/?id.304590
- ADVISORYhttps://vuldb.com/?submit.546414
- EXPLOIThttps://github.com/user-attachments/files/19580481/Assimp_MD3Importer_ValidateSurfaceHeaderOffsets-hbo.zip
- REPORThttps://github.com/assimp/assimp/issues/6070
- REPORThttps://vuldb.com/?ctiid.304590