CVE-2025-2757: Open Asset Import Library Assimp MD5 File MD5Parser.cpp AI_MD5_PARSE_STRING_IN_QUOTATION heap-based overflow
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AIMD5PARSESTRINGINQUOTATION of the file code/AssetLib/MD5/MD5Parser.cpp of the component MD5 File Handler. The manipulation of the argument data leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2757?
CVE-2025-2757 is classified as a critical vulnerability.
What components are affected by CVE-2025-2757?
CVE-2025-2757 affects the function AI_MD5_PARSE_STRING_IN_QUOTATION in the MD5 File Handler of Open Asset Import Library Assimp 5.4.3.
How do I fix CVE-2025-2757?
To fix CVE-2025-2757, update Open Asset Import Library Assimp to the latest version that resolves this vulnerability.
What type of vulnerability is CVE-2025-2757?
CVE-2025-2757 is a critical vulnerability that involves argument data manipulation in the MD5 parsing function.
What should I do if I am using Open Asset Import Library Assimp 5.4.3?
If you are using Open Asset Import Library Assimp 5.4.3, you should immediately assess your exposure to CVE-2025-2757 and apply the necessary updates.