Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-3549

Опубликовано: 14 апр. 2025
Источник: nvd
CVSS3: 5.3
CVSS3: 3.3
CVSS2: 4.3
EPSS Низкий

Описание

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/AssetLib/MD3/MD3Loader.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:assimp:assimp:5.4.3:*:*:*:*:*:*:*

EPSS

Процентиль: 12%
0.00043
Низкий

5.3 Medium

CVSS3

3.3 Low

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 5.3
ubuntu
5 месяцев назад

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/AssetLib/MD3/MD3Loader.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
redhat
5 месяцев назад

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/AssetLib/MD3/MD3Loader.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
debian
5 месяцев назад

A vulnerability, which was classified as critical, was found in Open A ...

CVSS3: 5.3
github
5 месяцев назад

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/AssetLib/MD3/MD3Loader.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 12%
0.00043
Низкий

5.3 Medium

CVSS3

3.3 Low

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-119