CVE-2025-3016

CVSS 3.1 Score 3.2 of 10 (low)

Details

Published Mar 31, 2025
Updated: Apr 17, 2025
CWE ID 863

Summary

CVE-2025-3016 is a recently identified vulnerability in Open Asset Import Library Assimp 5.4.3. This issue lies within the Assimp::MDLImporter::ParseTextureColorData function of the MDL File Handler, specifically in the code file MDLMaterialLoader.cpp. Manipulation of the mWidth and mHeight arguments results in excessive resource consumption, posing a potential risk. This vulnerability can be exploited remotely, making it critical to address. Upgrading to Assimp version 6.0 resolves this issue, with patch 5d2a7482312db2e866439a8c05a07ce1e718bed1 available for those who cannot immediately upgrade. It's strongly advised to apply the patch as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share