CVE-2025-5201

Severity CVSS v4.0:
MEDIUM
Type:
CWE-119 Buffer Errors
Publication date:
26/05/2025
Last modified:
05/06/2025

Description

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function LWOImporter::CountVertsAndFacesLWO2 of the file assimp/code/AssetLib/LWO/LWOLoader.cpp. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:assimp:assimp:*:*:*:*:*:*:*:* 5.4.3 (excluding)