CVE-2025-5202: Open Asset Import Library Assimp HL1MDLLoader.cpp validate_header out-of-bounds

3.3 CVSS

Description

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function HL1MDLLoader::validate_header of the file assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. In Open Asset Import Library Assimp 5.4.3 wurde eine problematische Schwachstelle ausgemacht. Das betrifft die Funktion HL1MDLLoader::validate_header der Datei assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp. Durch die Manipulation mit unbekannten Daten kann eine out-of-bounds read-Schwachstelle ausgenutzt werden. Der Angriff muss lokal angegangen werden. Der Exploit steht zur öffentlichen Verfügung.

Classification

CVE ID: CVE-2025-5202

CVSS Base Severity: LOW

CVSS Base Score: 3.3

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Problem Types

Out-of-Bounds Read Memory Corruption

Affected Products

Vendor: Open Asset Import Library

Product: Assimp

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 4.16% (scored less or equal to compared to others)

EPSS Date: 2025-06-06 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-5202
https://vuldb.com/?id.310291
https://vuldb.com/?ctiid.310291
https://vuldb.com/?submit.578007
https://github.com/assimp/assimp/issues/6174
https://github.com/assimp/assimp/issues/6128
https://github.com/user-attachments/files/20209236/reproducer.zip

Timeline