Vulnerability Description
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of the file code/AssetLib/LWO/LWOAnimation.cpp of the component LWO File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Assimp | Assimp | 5.4.3 |
Related Weaknesses (CWE)
References
- https://github.com/assimp/assimp/issues/6023ExploitIssue Tracking
- https://github.com/assimp/assimp/issues/6023#issue-2877381000ExploitIssue Tracking
- https://vuldb.com/?ctiid.303104Permissions RequiredVDB Entry
- https://vuldb.com/?id.303104Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.542246Third Party AdvisoryVDB Entry
FAQ
What is CVE-2025-3158?
CVE-2025-3158 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of t...
How severe is CVE-2025-3158?
CVE-2025-3158 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-3158?
Check the references section above for vendor advisories and patch information. Affected products include: Assimp Assimp.