CVE-2025-5202: Open Asset Import Library Assimp HL1MDLLoader.cpp validate_header out-of-bounds
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function HL1MDLLoader::validateheader of the file assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5202?
CVE-2025-5202 is classified as a problematic vulnerability that can lead to out-of-bounds access.
How do I fix CVE-2025-5202?
To fix CVE-2025-5202, update to the latest version of Open Asset Import Library Assimp that addresses this vulnerability.
What is the impact of CVE-2025-5202 on Open Asset Import Library Assimp?
The impact of CVE-2025-5202 includes potential exploitation through out-of-bounds access, which could lead to crashes or code execution.
Which function is vulnerable in CVE-2025-5202?
The vulnerable function in CVE-2025-5202 is HL1MDLLoader::validate_header within the HL1MDLLoader.cpp file.
Is CVE-2025-5202 present in earlier versions of Assimp?
Yes, CVE-2025-5202 is present in version 5.4.3 of Open Asset Import Library Assimp.