CVE-2025-2151
published 2025-03-10CVE-2025-2151: A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the…
medium5.3CVSS 4.0
AVNACLATNPRNUIPVCLVILVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| assimp | assimp | — | — |
| assimp | assimp | >= 0 < 6.0.2+ds-1 | 6.0.2+ds-1 |
| debian | assimp | < assimp 6.0.2+ds-1 (forky) | assimp 6.0.2+ds-1 (forky) |
| linux | linux_kernel | >= 2.6.12 < 5.4.301 | 5.4.301 |
| linux | linux_kernel | >= 5.11.0 < 5.15.196 | 5.15.196 |
| linux | linux_kernel | >= 5.16.0 < 6.1.158 | 6.1.158 |
| linux | linux_kernel | >= 5.5.0 < 5.10.246 | 5.10.246 |
| linux | linux_kernel | >= 6.13.0 < 6.17.6 | 6.17.6 |
| linux | linux_kernel | >= 6.2.0 < 6.6.115 | 6.6.115 |
| linux | linux_kernel | >= 6.7.0 < 6.12.56 | 6.12.56 |
| open_asset_import_library | assimp | — | — |
CVSS provenance
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.3MEDIUM