Open Asset Import Library Assimp是Open Asset Import Library开源的一个官方开放资产导入库存储库。可将40多种3D文件格式加载到一个统一且干净的数据结构中。 Open Asset Import Library Assimp 6.0.2版本存在安全漏洞,该漏洞源于ODDLParser::getNextSeparator函数存在堆缓冲区溢出,可能导致本地攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Open Asset Import Library | Assimp | 6.0.2 |
cpe:2.3:a:assimp:assimp:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-11277 | 5.3 MEDIUM | Open Asset Import Library Assimp Q3DLoader.cpp InternReadFile heap-based overflow |
| CVE-2025-11274 | 3.3 LOW | Open Asset Import Library Assimp Q3DLoader.cpp InternReadFile allocation of resources |
No comments yet