Open Asset Import Library Assimp 6.0.2 Q3DLoader.cpp InternReadFile Uskraćivanje usluge

Identifikovana je ranjivost klasifikovana kao Problematiиno u Open Asset Import Library Assimp 6.0.2. Obuhvaćeno je funkcija Q3DImporter::InternReadFile u fajlu assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Promena uzrokuje Uskraćivanje usluge. Korišćenje CWE za deklarisanje problema vodi do CWE-770. Objava slabosti je izvršena 10/04/2025 kao 6356. Obaveštenje je dostupno za preuzimanje na github.com. Ova ranjivost je označena kao CVE-2025-11274. Napad mora biti izveden lokalno. Tehnički detalji su dostupni. Штавише, експлоит је доступан. Eksploatacija je otkrivena javnosti i može biti iskorišćena. U ovom trenutku, trenutna cena za eksploataciju može iznositi oko USD $0-$5k. Označeno je kao dokaz-of-koncept. Eksploat je dostupan za preuzimanje na github.com. Kao 0-day, procenjena cena na crnom tržištu bila je oko $0-$5k. Ranljivost je takođe dokumentovana u drugim bazama podataka o ranjivostima: Tenable (269660). If you want to get best quality of vulnerability data, you may have to visit VulDB.

4 Promene · 90 Tačke podataka

PoljeKreirali
10/04/2025 08:07
Ažurira 1/3
10/05/2025 03:31
Ažurira 2/3
10/05/2025 05:05
Ažurira 3/3
10/11/2025 07:42
cvss4_vuldb_vaLLLL
cvss4_vuldb_ePPPP
cvss2_vuldb_auSSSS
cvss2_vuldb_rlNDNDNDND
cvss3_vuldb_rlXXXX
cvss4_vuldb_atNNNN
cvss4_vuldb_scNNNN
cvss4_vuldb_siNNNN
cvss4_vuldb_saNNNN
cvss2_vuldb_basescore1.71.71.71.7
cvss2_vuldb_tempscore1.51.51.51.5
cvss3_vuldb_basescore3.33.33.33.3
cvss3_vuldb_tempscore3.03.03.03.0
cvss3_meta_basescore3.33.33.33.3
cvss3_meta_tempscore3.03.03.13.1
cvss4_vuldb_bscore4.84.84.84.8
cvss4_vuldb_btscore1.91.91.91.9
advisory_date1759528800 (10/04/2025)1759528800 (10/04/2025)1759528800 (10/04/2025)1759528800 (10/04/2025)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k
software_vendorOpen Asset Import LibraryOpen Asset Import LibraryOpen Asset Import LibraryOpen Asset Import Library
software_nameAssimpAssimpAssimpAssimp
software_version6.0.26.0.26.0.26.0.2
software_fileassimp/code/AssetLib/Q3D/Q3DLoader.cppassimp/code/AssetLib/Q3D/Q3DLoader.cppassimp/code/AssetLib/Q3D/Q3DLoader.cppassimp/code/AssetLib/Q3D/Q3DLoader.cpp
software_functionQ3DImporter::InternReadFileQ3DImporter::InternReadFileQ3DImporter::InternReadFileQ3DImporter::InternReadFile
vulnerability_cweCWE-770 (Uskraćivanje usluge)CWE-770 (Uskraćivanje usluge)CWE-770 (Uskraćivanje usluge)CWE-770 (Uskraćivanje usluge)
vulnerability_risk1111
cvss3_vuldb_avLLLL
cvss3_vuldb_acLLLL
cvss3_vuldb_prLLLL
cvss3_vuldb_uiNNNN
cvss3_vuldb_sUUUU
cvss3_vuldb_cNNNN
cvss3_vuldb_iNNNN
cvss3_vuldb_aLLLL
cvss3_vuldb_ePPPP
cvss3_vuldb_rcRRRR
advisory_identifier6356635663566356
advisory_urlhttps://github.com/assimp/assimp/issues/6356https://github.com/assimp/assimp/issues/6356https://github.com/assimp/assimp/issues/6356https://github.com/assimp/assimp/issues/6356
exploit_availability1111
exploit_publicity1111
exploit_urlhttps://github.com/user-attachments/files/22407575/poc.ziphttps://github.com/user-attachments/files/22407575/poc.ziphttps://github.com/user-attachments/files/22407575/poc.ziphttps://github.com/user-attachments/files/22407575/poc.zip
source_cveCVE-2025-11274CVE-2025-11274CVE-2025-11274CVE-2025-11274
cna_responsibleVulDBVulDBVulDBVulDB
software_typeSoftware LibrarySoftware LibrarySoftware LibrarySoftware Library
cvss2_vuldb_avLLLL
cvss2_vuldb_acLLLL
cvss2_vuldb_ciNNNN
cvss2_vuldb_iiNNNN
cvss2_vuldb_aiPPPP
cvss2_vuldb_ePOCPOCPOCPOC
cvss2_vuldb_rcURURURUR
cvss4_vuldb_avLLLL
cvss4_vuldb_acLLLL
cvss4_vuldb_prLLLL
cvss4_vuldb_uiNNNN
cvss4_vuldb_vcNNNN
cvss4_vuldb_viNNNN
euvd_idEUVD-2025-32437EUVD-2025-32437EUVD-2025-32437
cve_nvd_summaryA vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of resources. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized.A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of resources. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized.
cvss4_cna_avLL
cvss4_cna_acLL
cvss4_cna_atNN
cvss4_cna_prLL
cvss4_cna_uiNN
cvss4_cna_vcNN
cvss4_cna_viNN
cvss4_cna_vaLL
cvss4_cna_scNN
cvss4_cna_siNN
cvss4_cna_saNN
cvss4_cna_bscore4.84.8
cvss3_cna_avLL
cvss3_cna_acLL
cvss3_cna_prLL
cvss3_cna_uiNN
cvss3_cna_sUU
cvss3_cna_cNN
cvss3_cna_iNN
cvss3_cna_aLL
cvss3_cna_basescore3.33.3
cvss2_cna_avLL
cvss2_cna_acLL
cvss2_cna_auSS
cvss2_cna_ciNN
cvss2_cna_iiNN
cvss2_cna_aiPP
cvss2_cna_basescore1.71.7
nessus_id269660
nessus_nameLinux Distros Unpatched Vulnerability : CVE-2025-11274

Want to stay up to date on a daily basis?

Enable the mail alert feature now!