Open Asset Import Library Assimp 6.0.2 Q3DLoader.cpp InternReadFile Kari na aiki

Hakika vulnerability da aka rarraba a matsayin karshewa an gano a Open Asset Import Library Assimp 6.0.2. Tabbas, aikin Q3DImporter::InternReadFile ne ke da matsala; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburare $software_library, a cikin fayil assimp/code/AssetLib/Q3D/Q3DLoader.cpp, a cikin sashi $software_component. Wuro manipulation ga Kari na aiki. Amfani da CWE wajen bayyana matsala yana kaiwa CWE-770. Lalle, rauni an sanar da shi 10/04/2025 da 6356. Ana samun bayanin tsaro don saukewa a github.com. Ana kiran wannan rauni da CVE-2025-11274. Wuroo ka a yiɗi a yi ɗum e gese. Bayani na fasaha ga. Kuma, akwai exploit. Exploit ɗin an bayyana wa jama'a, za a iya amfani da shi. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Á yí huɗɗi-na-gaskiya. Za a iya samun exploit a github.com. 0-day ga, an ndiyam a wuro be $0-$5k. An kuma rubuta wannan vulnerability a wasu kundin bayanan vulnerability: Tenable (269660). If you want to get best quality of vulnerability data, you may have to visit VulDB.

4 Goyarwa · 90 Datenpunkte

FurɗeSúgá
10/04/2025 08:07
Gargadi 1/3
10/05/2025 03:31
Gargadi 2/3
10/05/2025 05:05
Gargadi 3/3
10/11/2025 07:42
cvss4_vuldb_vaLLLL
cvss4_vuldb_ePPPP
cvss2_vuldb_auSSSS
cvss2_vuldb_rlNDNDNDND
cvss3_vuldb_rlXXXX
cvss4_vuldb_atNNNN
cvss4_vuldb_scNNNN
cvss4_vuldb_siNNNN
cvss4_vuldb_saNNNN
cvss2_vuldb_basescore1.71.71.71.7
cvss2_vuldb_tempscore1.51.51.51.5
cvss3_vuldb_basescore3.33.33.33.3
cvss3_vuldb_tempscore3.03.03.03.0
cvss3_meta_basescore3.33.33.33.3
cvss3_meta_tempscore3.03.03.13.1
cvss4_vuldb_bscore4.84.84.84.8
cvss4_vuldb_btscore1.91.91.91.9
advisory_date1759528800 (10/04/2025)1759528800 (10/04/2025)1759528800 (10/04/2025)1759528800 (10/04/2025)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k
software_vendorOpen Asset Import LibraryOpen Asset Import LibraryOpen Asset Import LibraryOpen Asset Import Library
software_nameAssimpAssimpAssimpAssimp
software_version6.0.26.0.26.0.26.0.2
software_fileassimp/code/AssetLib/Q3D/Q3DLoader.cppassimp/code/AssetLib/Q3D/Q3DLoader.cppassimp/code/AssetLib/Q3D/Q3DLoader.cppassimp/code/AssetLib/Q3D/Q3DLoader.cpp
software_functionQ3DImporter::InternReadFileQ3DImporter::InternReadFileQ3DImporter::InternReadFileQ3DImporter::InternReadFile
vulnerability_cweCWE-770 (Kari na aiki)CWE-770 (Kari na aiki)CWE-770 (Kari na aiki)CWE-770 (Kari na aiki)
vulnerability_risk1111
cvss3_vuldb_avLLLL
cvss3_vuldb_acLLLL
cvss3_vuldb_prLLLL
cvss3_vuldb_uiNNNN
cvss3_vuldb_sUUUU
cvss3_vuldb_cNNNN
cvss3_vuldb_iNNNN
cvss3_vuldb_aLLLL
cvss3_vuldb_ePPPP
cvss3_vuldb_rcRRRR
advisory_identifier6356635663566356
advisory_urlhttps://github.com/assimp/assimp/issues/6356https://github.com/assimp/assimp/issues/6356https://github.com/assimp/assimp/issues/6356https://github.com/assimp/assimp/issues/6356
exploit_availability1111
exploit_publicity1111
exploit_urlhttps://github.com/user-attachments/files/22407575/poc.ziphttps://github.com/user-attachments/files/22407575/poc.ziphttps://github.com/user-attachments/files/22407575/poc.ziphttps://github.com/user-attachments/files/22407575/poc.zip
source_cveCVE-2025-11274CVE-2025-11274CVE-2025-11274CVE-2025-11274
cna_responsibleVulDBVulDBVulDBVulDB
software_typeSoftware LibrarySoftware LibrarySoftware LibrarySoftware Library
cvss2_vuldb_avLLLL
cvss2_vuldb_acLLLL
cvss2_vuldb_ciNNNN
cvss2_vuldb_iiNNNN
cvss2_vuldb_aiPPPP
cvss2_vuldb_ePOCPOCPOCPOC
cvss2_vuldb_rcURURURUR
cvss4_vuldb_avLLLL
cvss4_vuldb_acLLLL
cvss4_vuldb_prLLLL
cvss4_vuldb_uiNNNN
cvss4_vuldb_vcNNNN
cvss4_vuldb_viNNNN
euvd_idEUVD-2025-32437EUVD-2025-32437EUVD-2025-32437
cve_nvd_summaryA vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of resources. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized.A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of resources. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized.
cvss4_cna_avLL
cvss4_cna_acLL
cvss4_cna_atNN
cvss4_cna_prLL
cvss4_cna_uiNN
cvss4_cna_vcNN
cvss4_cna_viNN
cvss4_cna_vaLL
cvss4_cna_scNN
cvss4_cna_siNN
cvss4_cna_saNN
cvss4_cna_bscore4.84.8
cvss3_cna_avLL
cvss3_cna_acLL
cvss3_cna_prLL
cvss3_cna_uiNN
cvss3_cna_sUU
cvss3_cna_cNN
cvss3_cna_iNN
cvss3_cna_aLL
cvss3_cna_basescore3.33.3
cvss2_cna_avLL
cvss2_cna_acLL
cvss2_cna_auSS
cvss2_cna_ciNN
cvss2_cna_iiNN
cvss2_cna_aiPP
cvss2_cna_basescore1.71.7
nessus_id269660
nessus_nameLinux Distros Unpatched Vulnerability : CVE-2025-11274

Interested in the pricing of exploits?

See the underground prices here!