CVE-2025-2754: Open Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection heap-based overflow
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument it leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2754?
CVE-2025-2754 has been declared as critical.
How do I fix CVE-2025-2754?
To fix CVE-2025-2754, upgrade to the latest version of Open Asset Import Library Assimp that addresses this vulnerability.
Which version of Open Asset Import Library Assimp is affected by CVE-2025-2754?
CVE-2025-2754 affects Open Asset Import Library Assimp version 5.4.3.
What component of Assimp is vulnerable in CVE-2025-2754?
The vulnerable component in CVE-2025-2754 is the AC3D File Handler function Assimp::AC3DImporter::ConvertObjectSection.
What type of issues does CVE-2025-2754 cause?
CVE-2025-2754 may allow for manipulation or exploitation through the AC3D File Handler in Assimp.