CVE-2025-2757

A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AI_MD5_PARSE_STRING_IN_QUOTATION of the file code/AssetLib/MD5/MD5Parser.cpp of the component MD5 File Handler. The manipulation of the argument data leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/assimp/assimp/issues/6019 Exploit Issue Tracking
https://github.com/assimp/assimp/issues/6019#issue-2877376386 Exploit Issue Tracking
https://vuldb.com/?ctiid.300862 Permissions Required VDB Entry
https://vuldb.com/?id.300862 Third Party Advisory VDB Entry
https://vuldb.com/?submit.517817 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:assimp:assimp:5.4.3:*:*:*:*:*:*:*

History

17 Jul 2025, 21:46

Type Values Removed Values Added
First Time Assimp assimp
Assimp
CPE cpe:2.3:a:assimp:assimp:5.4.3:*:*:*:*:*:*:*
References () https://github.com/assimp/assimp/issues/6019 - () https://github.com/assimp/assimp/issues/6019 - Exploit, Issue Tracking
References () https://github.com/assimp/assimp/issues/6019#issue-2877376386 - () https://github.com/assimp/assimp/issues/6019#issue-2877376386 - Exploit, Issue Tracking
References () https://vuldb.com/?ctiid.300862 - () https://vuldb.com/?ctiid.300862 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.300862 - () https://vuldb.com/?id.300862 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.517817 - () https://vuldb.com/?submit.517817 - Third Party Advisory, VDB Entry

27 Mar 2025, 16:45

Type Values Removed Values Added
Summary
  • (es) Se detectó una vulnerabilidad crítica en Open Asset Import Library Assimp 5.4.3. Esta vulnerabilidad afecta a la función AI_MD5_PARSE_STRING_IN_QUOTATION del archivo code/AssetLib/MD5/MD5Parser.cpp del componente MD5 File Handler. La manipulación de los datos de los argumentos provoca un desbordamiento del búfer basado en el montón. El ataque puede iniciarse remotamente. Se ha hecho público el exploit y puede que sea utilizado.

25 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-25 10:15

Updated : 2025-07-17 21:46


NVD link : CVE-2025-2757

Mitre link : CVE-2025-2757

CVE.ORG link : CVE-2025-2757


JSON object : View

Products Affected

assimp

  • assimp
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-122

Heap-based Buffer Overflow