CVE-2025-3548: Open Asset Import Library Assimp File types.h Set heap-based overflow
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp up to 5.4.3. This issue affects the function aiString::Set in the library include/assimp/types.h of the component File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3548?
CVE-2025-3548 is classified as a critical vulnerability.
How do I fix CVE-2025-3548?
To fix CVE-2025-3548, update Open Asset Import Library Assimp to version 5.4.4 or later.
What type of vulnerability is CVE-2025-3548?
CVE-2025-3548 is a heap-based buffer overflow vulnerability.
Which software is affected by CVE-2025-3548?
CVE-2025-3548 affects Open Asset Import Library Assimp versions up to 5.4.3.
What component of Open Asset Import Library is impacted by CVE-2025-3548?
CVE-2025-3548 impacts the aiString::Set function in the File Handler component.