CVE-2025-5204: Open Asset Import Library Assimp MDLMaterialLoader.cpp ParseSkinLump_3DGS_MDL7 out-of-bounds
A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::ParseSkinLump3DGSMDL7 of the file assimp/code/AssetLib/MDL/MDLMaterialLoader.cpp. The manipulation leads to out-of-bounds read. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5204?
CVE-2025-5204 is classified as problematic due to its potential for out-of-bounds read vulnerabilities.
How do I fix CVE-2025-5204?
To mitigate CVE-2025-5204, updating to a patched version of Open Asset Import Library Assimp is recommended.
What is affected by CVE-2025-5204?
CVE-2025-5204 affects Open Asset Import Library Assimp version 5.4.3.
Can CVE-2025-5204 be exploited remotely?
CVE-2025-5204 primarily affects local execution environments, making remote exploitation less likely.
What component of Assimp is vulnerable in CVE-2025-5204?
The vulnerability in CVE-2025-5204 is located in the function MDLImporter::ParseSkinLump_3DGS_MDL7 within the MDLMaterialLoader.cpp file.