CVE-2025-3160: Open Asset Import Library Assimp File SceneCombiner.cpp AddNodeHashes out-of-bounds
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the component File Handler. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as a0993658f40d8e13ff5823990c30b43c82a5daf0. It is recommended to apply a patch to fix this issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3160?
CVE-2025-3160 is classified as problematic due to potential issues in the Assimp library.
How do I fix CVE-2025-3160?
To fix CVE-2025-3160, upgrade to a patched version of Open Asset Import Library Assimp that resolves this vulnerability.
What components are affected by CVE-2025-3160?
CVE-2025-3160 affects the Assimp::SceneCombiner::AddNodeHashes function in the File Handler component.
What is the impact of CVE-2025-3160?
The impact of CVE-2025-3160 includes potential manipulation vulnerabilities that may affect application stability.
What versions of Assimp are vulnerable to CVE-2025-3160?
CVE-2025-3160 affects Open Asset Import Library Assimp version 5.4.3 specifically.