CVE-2025-3549: Open Asset Import Library Assimp File MD3Loader.cpp ValidateSurfaceHeaderOffsets heap-based overflow
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/AssetLib/MD3/MD3Loader.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3549?
CVE-2025-3549 is classified as a critical vulnerability.
How do I fix CVE-2025-3549?
To fix CVE-2025-3549, update to the latest version of Open Asset Import Library Assimp that addresses this vulnerability.
What component is affected by CVE-2025-3549?
CVE-2025-3549 affects the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets in the File Handler component.
What type of vulnerability is CVE-2025-3549?
CVE-2025-3549 is a heap manipulation vulnerability.
Which version of Assimp is affected by CVE-2025-3549?
CVE-2025-3549 affects Open Asset Import Library Assimp version 5.4.3.