CVE-2025-5203

Source
https://cve.org/CVERecord?id=CVE-2025-5203
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-5203.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-5203
Downstream
Published
2025-05-26T20:15:19.987Z
Modified
2026-03-15T22:51:02.265401Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this issue is the function SkipSpaces in the library assimp/include/assimp/ParsingUtils.h. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.

References

Affected packages

Git / github.com/assimp/assimp

Affected ranges

Type
GIT
Repo
https://github.com/assimp/assimp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.4.3"
        }
    ]
}

Affected versions

5.*
5.2.0
Release3.*
Release3.1_RC1
v.*
v.5.0.0.rc1
v.5.0.0.rc2
v3.*
v3.1
v3.1-rc2
v3.1.1
v3.2
v3.3
v3.3.1
v4.*
v4.0.0
v4.0.0.rc1
v4.0.1
v4.1.0
v5.*
v5.0.0
v5.1.0
v5.1.0.rc1
v5.1.1
v5.1.2
v5.1.3
v5.1.4
v5.1.5
v5.1.6
v5.2.0
v5.2.1
v5.2.2
v5.2.3
v5.2.4
v5.2.5
v5.3.0
v5.3.1
v5.4.0
v5.4.1
v5.4.2

Database specific

vanir_signatures
[
    {
        "target": {
            "file": "test/unit/utVersion.cpp"
        },
        "id": "CVE-2025-5203-20a4c35d",
        "digest": {
            "line_hashes": [
                "14751536908339836394842576333578963310",
                "250465586554798767444559000961914664081",
                "237443928289347941562880826078082366790",
                "259836610294362557380643058981394434250"
            ],
            "threshold": 0.9
        },
        "source": "https://github.com/assimp/assimp/commit/c35200e38ea8f058812b83de2ef32c6093b0ece2",
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "TEST_F",
            "file": "test/unit/utVersion.cpp"
        },
        "id": "CVE-2025-5203-cea7f02c",
        "digest": {
            "function_hash": "122993617034958603430649906656648264306",
            "length": 63.0
        },
        "source": "https://github.com/assimp/assimp/commit/c35200e38ea8f058812b83de2ef32c6093b0ece2",
        "signature_version": "v1",
        "deprecated": false,
        "signature_type": "Function"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-5203.json"