CVE-2025-3160

medium

Description

A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the component File Handler. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as a0993658f40d8e13ff5823990c30b43c82a5daf0. It is recommended to apply a patch to fix this issue.

References

https://vuldb.com/?submit.542248

https://vuldb.com/?id.303106

https://vuldb.com/?ctiid.303106

https://github.com/assimp/assimp/pull/6049

https://github.com/assimp/assimp/issues/6025#issue-2877385383

https://github.com/assimp/assimp/issues/6025

https://github.com/assimp/assimp/commit/a0993658f40d8e13ff5823990c30b43c82a5daf0

Details

Source: Mitre, NVD

Published: 2025-04-03

Updated: 2025-04-03

Risk Information

CVSS v2

Base Score: 1.7

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 3.3

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Severity: Low

CVSS v4

Base Score: 4.8

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Severity: Medium