Debian Assimp vulnerabilities
26 known vulnerabilities affecting debian/assimp.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM22
Vulnerabilities
Page 2 of 2
CVE-2025-2591P4MEDIUMCVSS 5.3fixed in assimp 6.0.2+ds-1 (forky)2025
CVE-2025-2591 [MEDIUM] CVE-2025-2591: assimp - A vulnerability classified as problematic was found in Open Asset Import Library...
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function MDLImporter::InternReadFile_Quake1 of the file code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument skinwidth/skinheight leads to divide by zero. The attack can be initiated remotely. The exploit has been disclosed to the
debian
CVE-2021-45948P4MEDIUMCVSS 5.5fixed in assimp 5.1.1~ds0-1 (bookworm)2021
CVE-2021-45948 [MEDIUM] CVE-2021-45948: assimp - Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer o...
Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in _m3d_safestr (called from m3d_load and Assimp::M3DWrapper::M3DWrapper).
Scope: local
bookworm: resolved (fixed in 5.1.1~ds0-1)
bullseye: resolved
forky: resolved (fixed in 5.1.1~ds0-1)
sid: resolved (fixed in 5.1.1~ds0-1)
trixie: resolved (fixed in 5.1.1~ds0-1)
debian
CVE-2024-48425P4MEDIUMCVSS 5.5fixed in assimp 6.0.2+ds-1 (forky)2024
CVE-2024-48425 [MEDIUM] CVE-2024-48425: assimp - A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_...
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference.
Scope: local
bookworm: open
bul
debian
CVE-2025-3549P4MEDIUMCVSS 4.8fixed in assimp 6.0.3+ds-1 (forky)2025
CVE-2025-3549 [MEDIUM] CVE-2025-3549: assimp - A vulnerability, which was classified as critical, was found in Open Asset Impor...
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/AssetLib/MD3/MD3Loader.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has be
debian
CVE-2025-3548P4MEDIUMCVSS 4.8fixed in assimp 6.0.2+ds-1 (forky)2025
CVE-2025-3548 [MEDIUM] CVE-2025-3548: assimp - A vulnerability, which was classified as critical, has been found in Open Asset ...
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp up to 5.4.3. This issue affects the function aiString::Set in the library include/assimp/types.h of the component File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed
debian
CVE-2025-3160P4MEDIUMCVSS 4.8fixed in assimp 6.0.2+ds-1 (forky)2025
CVE-2025-3160 [MEDIUM] CVE-2025-3160: assimp - A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and cla...
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the component File Handler. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclose
debian
← Previous2 / 2