CVE-2025-6120

low

Description

A vulnerability classified as critical was found in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerability is the function read_meshes in the library assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.

References

https://vuldb.com/?submit.591235

https://vuldb.com/?id.312589

https://vuldb.com/?ctiid.312589

https://github.com/user-attachments/files/20605340/read_meshes_reproduce.tar.gz

https://github.com/assimp/assimp/issues/6220#issuecomment-2945018579

https://github.com/assimp/assimp/issues/6220

Details

Source: Mitre, NVD

Published: 2025-06-16

Updated: 2025-06-16

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Severity: Medium

CVSS v4

Base Score: 1.9

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Severity: Low

EPSS

EPSS: 0.00013