CVE-2025-2152

A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of the file BaseImporter.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/assimp/assimp/issues/6027 Exploit Issue Tracking
https://github.com/assimp/assimp/issues/6027#issue-2877629241 Exploit Issue Tracking
https://vuldb.com/?ctiid.299063 Permissions Required VDB Entry
https://vuldb.com/?id.299063 Third Party Advisory VDB Entry
https://vuldb.com/?submit.510818 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:assimp:assimp:5.4.3:*:*:*:*:*:*:*

History

13 Mar 2025, 18:15

Type Values Removed Values Added
First Time Assimp
Assimp assimp
CWE CWE-787
CPE cpe:2.3:a:assimp:assimp:5.4.3:*:*:*:*:*:*:*
References () https://github.com/assimp/assimp/issues/6027 - () https://github.com/assimp/assimp/issues/6027 - Exploit, Issue Tracking
References () https://github.com/assimp/assimp/issues/6027#issue-2877629241 - () https://github.com/assimp/assimp/issues/6027#issue-2877629241 - Exploit, Issue Tracking
References () https://vuldb.com/?ctiid.299063 - () https://vuldb.com/?ctiid.299063 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.299063 - () https://vuldb.com/?id.299063 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.510818 - () https://vuldb.com/?submit.510818 - Third Party Advisory, VDB Entry
Summary
  • (es) Se ha encontrado una vulnerabilidad, que se ha clasificado como crítica, en Open Asset Import Library Assimp 5.4.3. Este problema afecta a la función Assimp::BaseImporter::ConvertToUTF8 del archivo BaseImporter.cpp del componente File Handler. La manipulación provoca un desbordamiento del búfer basado en el montón. El ataque puede iniciarse de forma remota. El exploit se ha hecho público y puede utilizarse.

10 Mar 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-10 14:15

Updated : 2025-03-13 18:15


NVD link : CVE-2025-2152

Mitre link : CVE-2025-2152

CVE.ORG link : CVE-2025-2152


JSON object : View

Products Affected

assimp

  • assimp
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write