CVE-2025-2755

Severity CVSS v4.0:
MEDIUM
Type:
CWE-119 Buffer Errors
Publication date:
25/03/2025
Last modified:
17/07/2025

Description

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument src.entries leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:assimp:assimp:5.4.3:*:*:*:*:*:*:*