CVE-2025-11274: Open Asset Import Library Assimp Q3DLoader.cpp InternReadFile allocation of resources
A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of resources. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11274?
CVE-2025-11274 is classified as a moderate-severity vulnerability due to its potential for local resource allocation manipulation.
How do I fix CVE-2025-11274?
To fix CVE-2025-11274, update Open Asset Import Library Assimp to version 6.0.3 or later.
Who is affected by CVE-2025-11274?
CVE-2025-11274 affects users running Open Asset Import Library Assimp version 6.0.2.
Can CVE-2025-11274 be exploited remotely?
No, CVE-2025-11274 can only be exploited through local execution.
What is the function involved in CVE-2025-11274?
CVE-2025-11274 involves a vulnerability in the function Q3DImporter::InternReadFile in Q3DLoader.cpp.