VYPR

rpm package

opensuse/assimp&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/assimp&distro=openSUSE%20Tumbleweed

Vulnerabilities (30)

  • CVE-2025-2591MedMar 21, 2025
    affected < 5.4.3-5.1fixed 5.4.3-5.1

    A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function MDLImporter::InternReadFile_Quake1 of the file code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument skinwidth/skinheight leads to di

  • CVE-2025-2152MedMar 10, 2025
    affected < 6.0.1-1.1fixed 6.0.1-1.1

    A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of the file BaseImporter.cpp of the component File Handler. The manipulation leads to heap-based buffer

  • CVE-2025-2151MedMar 10, 2025
    affected < 5.4.3-4.1fixed 5.4.3-4.1

    A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack c

  • CVE-2024-53425MedNov 21, 2024
    affected < 5.4.3-3.1fixed 5.4.3-3.1

    A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash.

  • CVE-2024-48426MedOct 24, 2024
    affected < 6.0.1-1.1fixed 6.0.1-1.1

    A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971).

  • CVE-2024-48425MedOct 24, 2024
    affected < 5.4.3-3.1fixed 5.4.3-3.1

    A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero

  • CVE-2024-48424MedOct 24, 2024
    affected < 5.4.3-3.1fixed 5.4.3-3.1

    A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.

  • CVE-2024-48423HigOct 24, 2024
    affected < 5.4.3-3.1fixed 5.4.3-3.1

    An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.

  • CVE-2024-45679HigSep 18, 2024
    affected < 5.4.3-2.1fixed 5.4.3-2.1

    Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a specially crafted file into the product.

  • CVE-2024-40724HigJul 19, 2024
    affected < 5.4.3-1.1fixed 5.4.3-1.1

    Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary code by inputting a specially crafted file into the product.

Page 2 of 2