A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::InternReadFile_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.
References
Link | Resource |
---|---|
https://github.com/assimp/assimp/issues/6128 | Issue Tracking |
https://github.com/assimp/assimp/issues/6171 | Exploit |
https://github.com/user-attachments/files/20208891/reproducer.zip | Exploit |
https://vuldb.com/?ctiid.310257 | Permissions Required VDB Entry |
https://vuldb.com/?id.310257 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.578004 | Third Party Advisory VDB Entry |
https://github.com/assimp/assimp/issues/6171 | Exploit |
Configurations
History
03 Jun 2025, 15:41
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/assimp/assimp/issues/6128 - Issue Tracking | |
References | () https://github.com/assimp/assimp/issues/6171 - Exploit | |
References | () https://github.com/user-attachments/files/20208891/reproducer.zip - Exploit | |
References | () https://vuldb.com/?ctiid.310257 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.310257 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.578004 - Third Party Advisory, VDB Entry | |
CPE | cpe:2.3:a:assimp:assimp:5.4.3:*:*:*:*:*:*:* | |
First Time |
Assimp assimp
Assimp |
28 May 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/assimp/assimp/issues/6171 - |
28 May 2025, 15:01
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
26 May 2025, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-26 05:15
Updated : 2025-06-03 15:41
NVD link : CVE-2025-5169
Mitre link : CVE-2025-5169
CVE.ORG link : CVE-2025-5169
JSON object : View
Products Affected
assimp
- assimp