CVE-2025-3159
Open Asset Import Library Assimp ASE File ASEParser.cpp ParseLV4MeshBonesVertices heap-based overflow
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.8EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
03 abr 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component ASE File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is e8a6286542924e628e02749c4f5ac4f91fdae71b. It is recommended to apply a patch to fix this issue.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Productos afectados
Open Asset Import Library · Assimp¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://github.com/assimp/assimp/issues/6024https://github.com/assimp/assimp/issues/6024#issue-2877382033https://github.com/assimp/assimp/pull/6051https://github.com/tellypresence/assimp/commit/e8a6286542924e628e02749c4f5ac4f91fdae71bhttps://vuldb.com/?ctiid.303105https://vuldb.com/?id.303105https://vuldb.com/?submit.542247