Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-70067

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation

A flaw was found in Assimp, an open-source asset import library, specifically within its FBX Importer. This buffer overflow vulnerability occurs when processing a specially crafted FBX file. An attacker could exploit this by providing a malicious FBX file, causing a property key string to be copied into a fixed-size memory buffer without proper length validation. This could lead to a denial of service or potentially arbitrary code execution, allowing an attacker to run unauthorized commands.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10qt6-qtquick3dFix deferred
Red Hat Enterprise Linux 9qt5-qt3dNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2465308Assimp: Assimp: Buffer overflow in FBX Importer allows arbitrary code execution via crafted file.

EPSS

Процентиль: 26%
0.0034
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation

CVSS3: 9.8
nvd
3 месяца назад

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation

CVSS3: 9.8
debian
3 месяца назад

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in ...

CVSS3: 9.8
redos
около 1 месяца назад

Уязвимость assimp

CVSS3: 9.8
github
3 месяца назад

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation

EPSS

Процентиль: 26%
0.0034
Низкий

5.6 Medium

CVSS3