Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-11277

Опубликовано: 05 окт. 2025
Источник: debian
EPSS Низкий

Описание

A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be exploited.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
assimpunfixedpackage
assimppostponedtrixiepackage
assimppostponedbookwormpackage
assimppostponedbullseyepackage

Примечания

  • https://github.com/assimp/assimp/issues/6358

  • https://github.com/assimp/assimp/pull/6370

  • Fixed by: https://github.com/assimp/assimp/commit/0978918f7148fbcd3d05cc6573dae7859975a895

EPSS

Процентиль: 8%
0.0003
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be exploited.

CVSS3: 5.3
nvd
2 месяца назад

A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be exploited.

rocky
16 дней назад

Moderate: qt6-qtquick3d security update

rocky
27 дней назад

Moderate: qt5-qt3d security update

rocky
27 дней назад

Moderate: qt5-qt3d security update

EPSS

Процентиль: 8%
0.0003
Низкий