Open Asset Import Library Assimp File types.h Set heap-based overflow
Published Apr 14, 2025
4.8
MEDIUMCVSS 4.0
EPSS 0.28%
Description
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp up to 5.4.3. This issue affects the function aiString::Set in the library include/assimp/types.h of the component File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
Affected products
-
- Version 5.4.0StatusaffectedConstraints-
- Version 5.4.1StatusaffectedConstraints-
- Version 5.4.2StatusaffectedConstraints-
- Version 5.4.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Open Asset Import Library | Assimp | n/a |
|
No data.
Red Hat Enterprise Linux 9
qt5-qt3d
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | qt5-qt3d | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (11)
- https://access.redhat.com/security/cve/CVE-2025-3548 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2359372 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10859 Advisory
- https://github.com/assimp/assimp/issues/6068 issue-trackingExploitIssue Tracking
- https://github.com/assimp/assimp/pull/6073 issue-trackingpatchIssue Tracking
- https://github.com/user-attachments/files/19580584/aiString_Set-hbo.zip exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-3548
- https://vuldb.com/?ctiid.304589 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.304589 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.546413 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.cve.org/CVERecord?id=CVE-2025-3548
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-3548 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2359372 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10859 | Advisory | |
| https://github.com/assimp/assimp/issues/6068 | issue-trackingExploitIssue Tracking | |
| https://github.com/assimp/assimp/pull/6073 | issue-trackingpatchIssue Tracking | |
| https://github.com/user-attachments/files/19580584/aiString_Set-hbo.zip | exploit | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-3548 | ||
| https://vuldb.com/?ctiid.304589 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.304589 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.546413 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.cve.org/CVERecord?id=CVE-2025-3548 |
Change history (0)
No recorded changes yet.