Open Asset Import Library Assimp LWOLoader.cpp CountVertsAndFacesLWO2 out-of-bounds
Published May 26, 2025
4.8
MEDIUMCVSS 4.0
EPSS 0.28%
Description
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function LWOImporter::CountVertsAndFacesLWO2 of the file assimp/code/AssetLib/LWO/LWOLoader.cpp. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.
Affected products
-
- Version 5.4.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Open Asset Import Library | Assimp | n/a |
|
No data.
Red Hat Enterprise Linux 9
qt5-qt3d
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | qt5-qt3d | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (11)
- https://access.redhat.com/security/cve/CVE-2025-5201 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2369039 Issue Tracking
- https://github.com/assimp/assimp/issues/6128 issue-trackingIssue Tracking
- https://github.com/assimp/assimp/issues/6173 issue-trackingExploitIssue Tracking
- https://github.com/assimp/assimp/issues/6174 exploitIssue Tracking
- https://github.com/user-attachments/files/20209125/line-832-reproducer.zip exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-5201
- https://vuldb.com/?ctiid.310290 signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry
- https://vuldb.com/?id.310290 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.578006 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.cve.org/CVERecord?id=CVE-2025-5201
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-5201 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2369039 | Issue Tracking | |
| https://github.com/assimp/assimp/issues/6128 | issue-trackingIssue Tracking | |
| https://github.com/assimp/assimp/issues/6173 | issue-trackingExploitIssue Tracking | |
| https://github.com/assimp/assimp/issues/6174 | exploitIssue Tracking | |
| https://github.com/user-attachments/files/20209125/line-832-reproducer.zip | exploit | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-5201 | ||
| https://vuldb.com/?ctiid.310290 | signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?id.310290 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.578006 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.cve.org/CVERecord?id=CVE-2025-5201 |
Change history (0)
No recorded changes yet.