cbcvebase.

Debian Assimp vulnerabilities

26 known vulnerabilities affecting debian/assimp.

Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM22

Vulnerabilities

Page 1 of 2
CVE-2025-2152P2MEDIUMCVSS 5.3fixed in assimp 6.0.2+ds-1 (forky)2025
CVE-2025-2152 [MEDIUM] CVE-2025-2152: assimp - A vulnerability, which was classified as critical, has been found in Open Asset ... A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of the file BaseImporter.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the pu
debian
CVE-2025-2151P3MEDIUMCVSS 5.3fixed in assimp 6.0.2+ds-1 (forky)2025
CVE-2025-2151 [MEDIUM] CVE-2025-2151: assimp - A vulnerability classified as critical was found in Open Asset Import Library As... A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. S
debian
CVE-2025-2592P3MEDIUMCVSS 5.3fixed in assimp 6.0.2+ds-1 (forky)2025
CVE-2025-2592 [MEDIUM] CVE-2025-2592: assimp - A vulnerability, which was classified as critical, has been found in Open Asset ... A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. T
debian
CVE-2025-2757P3MEDIUMCVSS 5.3fixed in assimp 6.0.2+ds-1 (forky)2025
CVE-2025-2757 [MEDIUM] CVE-2025-2757: assimp - A vulnerability classified as critical was found in Open Asset Import Library As... A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AI_MD5_PARSE_STRING_IN_QUOTATION of the file code/AssetLib/MD5/MD5Parser.cpp of the component MD5 File Handler. The manipulation of the argument data leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit
debian
CVE-2025-3015P3MEDIUMCVSS 5.3fixed in assimp 6.0.2+ds-1 (forky)2025
CVE-2025-3015 [MEDIUM] CVE-2025-3015: assimp - A vulnerability classified as critical has been found in Open Asset Import Libra... A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE File Handler. The manipulation of the argument mIndices leads to out-of-bounds read. It is possible to initiate the attack remotely. T
debian
CVE-2025-2750P3MEDIUMCVSS 5.3fixed in assimp 6.0.2+ds-1 (forky)2025
CVE-2025-2750 [MEDIUM] CVE-2025-2750: assimp - A vulnerability, which was classified as critical, was found in Open Asset Impor... A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation leads to out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been disclose
debian
CVE-2025-2751P3MEDIUMCVSS 5.3fixed in assimp 6.0.2+ds-1 (forky)2025
CVE-2025-2751 [MEDIUM] CVE-2025-2751: assimp - A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and cla... A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation of the argument na leads to out-of-bounds read. The attack can be initiated remotely. The exp
debian
CVE-2025-11277P3MEDIUMCVSS 4.8fixed in assimp 6.0.3+ds-1 (forky)2025
CVE-2025-11277 [MEDIUM] CVE-2025-11277: assimp - A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This a... A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks.
debian
CVE-2024-45679P3HIGHCVSS 8.4fixed in assimp 5.4.0+ds-1 (forky)2024
CVE-2024-45679 [HIGH] CVE-2024-45679: assimp - Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allow... Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a specially crafted file into the product. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 5.4.0+ds-1) sid: resolved (fixed in 5.4.0+ds-1) trixie: resolved (fixed in 5.4.0+ds-1)
debian
CVE-2025-3159P3MEDIUMCVSS 4.8fixed in assimp 6.0.2+ds-1 (forky)2025
CVE-2025-3159 [MEDIUM] CVE-2025-3159: assimp - A vulnerability, which was classified as critical, was found in Open Asset Impor... A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component ASE File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has
debian
CVE-2024-40724P3HIGHCVSS 7.8fixed in assimp 5.4.2+ds-1 (forky)2024
CVE-2024-40724 [HIGH] CVE-2024-40724: assimp - Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allow... Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary code by inputting a specially crafted file into the product. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 5.4.2+ds-1) sid: resolved (fixed in 5.4.2+ds-1) trixie: resolved (fixed in 5.4.2+ds-1)
debian
CVE-2025-3158P3MEDIUMCVSS 4.8fixed in assimp 6.0.2+ds-1 (forky)2025
CVE-2025-3158 [MEDIUM] CVE-2025-3158: assimp - A vulnerability, which was classified as critical, has been found in Open Asset ... A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of the file code/AssetLib/LWO/LWOAnimation.cpp of the component LWO File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack o
debian
CVE-2022-45748P3HIGHCVSS 8.8fixed in assimp 5.3.1+ds-2 (forky)2022
CVE-2022-45748 [HIGH] CVE-2022-45748: assimp - An issue was discovered with assimp 5.1.4, a use after free occurred in function... An issue was discovered with assimp 5.1.4, a use after free occurred in function ColladaParser::ExtractDataObjectFromChannel in file /code/AssetLib/Collada/ColladaParser.cpp. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 5.3.1+ds-2) sid: resolved (fixed in 5.3.1+ds-2) trixie: resolved (fixed in 5.3.1+ds-2)
debian
CVE-2024-48423P3HIGHCVSS 7.8fixed in assimp 6.0.2+ds-1 (forky)2024
CVE-2024-48423 [HIGH] CVE-2024-48423: assimp - An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via... An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 6.0.2+ds-1) sid: resolved (fixed in 6.0.2+ds-1) trixie: open
debian
CVE-2025-3016P4MEDIUMCVSS 5.3fixed in assimp 6.0.2+ds-1 (forky)2025
CVE-2025-3016 [MEDIUM] CVE-2025-3016: assimp - A vulnerability classified as problematic was found in Open Asset Import Library... A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the component MDL File Handler. The manipulation of the argument mWidth/mHeight leads to resource consumption. The attack can be initiat
debian
CVE-2025-3196P4MEDIUMCVSS 4.8fixed in assimp 6.0.2+ds-1 (forky)2025
CVE-2025-3196 [MEDIUM] CVE-2025-3196: assimp - A vulnerability, which was classified as critical, was found in Open Asset Impor... A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD2Importer::InternReadFile in the library code/AssetLib/MD2/MD2Loader.cpp of the component Malformed File Handler. The manipulation of the argument Name leads to stack-based buffer overflow. The attack needs to be approached locall
debian
CVE-2025-5165P4MEDIUMCVSS 4.8fixed in assimp 6.0.3+ds-1 (forky)2025
CVE-2025-5165 [MEDIUM] CVE-2025-5165: assimp - A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classifi... A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDCImporter::ValidateSurfaceHeader of the file assimp/code/AssetLib/MDC/MDCLoader.cpp. The manipulation of the argument pcSurface2 leads to out-of-bounds read. Attacking locally is a requirement. The exploit has been disclosed to the publ
debian
CVE-2024-53425P4MEDIUMCVSS 6.2fixed in assimp 6.0.2+ds-1 (forky)2024
CVE-2024-53425 [MEDIUM] CVE-2024-53425: assimp - A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd ... A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 6.0.2+ds-1) sid: resolved (fixed in 6.0.2+ds-1) trixie:
debian
CVE-2025-5166P4MEDIUMCVSS 4.8fixed in assimp 6.0.3+ds-1 (forky)2025
CVE-2025-5166 [MEDIUM] CVE-2025-5166: assimp - A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been... A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function MDCImporter::InternReadFile of the file assimp/code/AssetLib/MDC/MDCLoader.cpp of the component MDC File Parser. The manipulation of the argument pcVerts leads to out-of-bounds read. It is possible to launch the attack on the local host
debian
CVE-2024-48424P4MEDIUMCVSS 5.5fixed in assimp 6.0.2+ds-1 (forky)2024
CVE-2024-48424 [MEDIUM] CVE-2024-48424: assimp - A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::p... A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 6.0.2+ds-1) sid: resolved (fixed in 6.0.2+ds-1) trixie: open
debian
Debian Assimp vulnerabilities | cvebase