CVE-2025-11277: Open Asset Import Library Assimp Q3DLoader.cpp InternReadFile heap-based overflow
A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks.
Other sources
A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be exploited.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11277?
CVE-2025-11277 has not yet been assigned a specific severity score, but it is classified as a vulnerability that could facilitate a heap-based buffer overflow.
How do I fix CVE-2025-11277?
To fix CVE-2025-11277, update to the latest version of Open Asset Import Library Assimp, following best practices for secure coding and input handling.
Who is affected by CVE-2025-11277?
CVE-2025-11277 affects users of Open Asset Import Library Assimp version 6.0.2 and possibly earlier versions that implement the Q3DImporter functionality.
What kind of attack does CVE-2025-11277 allow?
CVE-2025-11277 allows a local attacker to exploit the vulnerability via manipulation to trigger a heap-based buffer overflow.
When was CVE-2025-11277 reported?
Details regarding the reporting date for CVE-2025-11277 are not provided, but the vulnerability affects version 6.0.2 of the software.