CVE-2025-3158: Open Asset Import Library Assimp LWO File LWOAnimation.cpp UpdateAnimRangeSetup heap-based overflow
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of the file code/AssetLib/LWO/LWOAnimation.cpp of the component LWO File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3158?
CVE-2025-3158 is classified as a critical vulnerability.
How do I fix CVE-2025-3158?
To fix CVE-2025-3158, you should update Open Asset Import Library Assimp to the latest version.
Which software versions are affected by CVE-2025-3158?
CVE-2025-3158 affects Open Asset Import Library Assimp version 5.4.3.
What component is impacted by CVE-2025-3158?
The function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup in the LWO File Handler is impacted by CVE-2025-3158.
Is CVE-2025-3158 exploitable?
Yes, CVE-2025-3158 is exploitable and can lead to critical consequences if not mitigated.