A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function MDLImporter::InternReadFile_Quake1 of the file code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument skinwidth/skinheight leads to divide by zero. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is identified as ab66a1674fcfac87aaba4c8b900b315ebc3e7dbd. It is recommended to apply a patch to fix this issue.
References
Link | Resource |
---|---|
https://github.com/assimp/assimp/issues/6009 | Exploit Issue Tracking |
https://github.com/assimp/assimp/issues/6009#issue-2877367021 | Exploit Issue Tracking |
https://github.com/assimp/assimp/pull/6047 | Patch |
https://github.com/assimp/assimp/pull/6047/commits/ab66a1674fcfac87aaba4c8b900b315ebc3e7dbd | Patch |
https://vuldb.com/?ctiid.300574 | Permissions Required VDB Entry |
https://vuldb.com/?id.300574 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.517781 | Third Party Advisory VDB Entry |
Configurations
History
17 Jul 2025, 21:53
Type | Values Removed | Values Added |
---|---|---|
First Time |
Assimp assimp
Assimp |
|
CPE | cpe:2.3:a:assimp:assimp:5.4.3:*:*:*:*:*:*:* | |
Summary |
|
|
References | () https://github.com/assimp/assimp/issues/6009 - Exploit, Issue Tracking | |
References | () https://github.com/assimp/assimp/issues/6009#issue-2877367021 - Exploit, Issue Tracking | |
References | () https://github.com/assimp/assimp/pull/6047 - Patch | |
References | () https://github.com/assimp/assimp/pull/6047/commits/ab66a1674fcfac87aaba4c8b900b315ebc3e7dbd - Patch | |
References | () https://vuldb.com/?ctiid.300574 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.300574 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.517781 - Third Party Advisory, VDB Entry |
21 Mar 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-21 14:15
Updated : 2025-07-17 21:53
NVD link : CVE-2025-2591
Mitre link : CVE-2025-2591
CVE.ORG link : CVE-2025-2591
JSON object : View
Products Affected
assimp
- assimp