Open Asset Import Library Assimp MDC File Parser MDCLoader.cpp InternReadFile out-of-bounds
Published May 26, 2025
4.8
MEDIUMCVSS 4.0
EPSS 0.26%
Description
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function MDCImporter::InternReadFile of the file assimp/code/AssetLib/MDC/MDCLoader.cpp of the component MDC File Parser. The manipulation of the argument pcVerts leads to out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.
Affected products
-
- Version 5.4.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Open Asset Import Library | Assimp | n/a |
|
No data.
Red Hat Enterprise Linux 9
qt5-qt3d
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | qt5-qt3d | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2025-5166 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2368508 Issue Tracking
- https://github.com/assimp/assimp/issues/6128 issue-trackingIssue Tracking
- https://github.com/assimp/assimp/issues/6168 exploitissue-tracking
- https://github.com/user-attachments/files/20208318/reproducer.zip exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-5166
- https://vuldb.com/?ctiid.310254 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.310254 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.578001 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.cve.org/CVERecord?id=CVE-2025-5166
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-5166 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2368508 | Issue Tracking | |
| https://github.com/assimp/assimp/issues/6128 | issue-trackingIssue Tracking | |
| https://github.com/assimp/assimp/issues/6168 | exploitissue-tracking | |
| https://github.com/user-attachments/files/20208318/reproducer.zip | exploit | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-5166 | ||
| https://vuldb.com/?ctiid.310254 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.310254 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.578001 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.cve.org/CVERecord?id=CVE-2025-5166 |
Change history (0)
No recorded changes yet.