CVE-2025-5167: Open Asset Import Library Assimp LWOLoader.h GetS0 out-of-bounds
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function LWOImporter::GetS0 in the library assimp/code/AssetLib/LWO/LWOLoader.h. The manipulation of the argument out leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5167?
CVE-2025-5167 is classified as a critical vulnerability due to its potential to cause out-of-bounds write conditions.
How do I fix CVE-2025-5167?
To fix CVE-2025-5167, you should update the Open Asset Import Library Assimp to version 5.4.4 or later.
What are the risks associated with CVE-2025-5167?
The risks of CVE-2025-5167 include potential application crashes and arbitrary code execution due to memory corruption.
Which function is affected by CVE-2025-5167?
CVE-2025-5167 specifically affects the function LWOImporter::GetS0 in the Assimp library.
Is CVE-2025-5167 exploitable in all environments?
CVE-2025-5167 may be exploitable in any environment using the vulnerable version of the Open Asset Import Library Assimp library.