CVE-2025-3159 | Open Asset Import Library Assimp 5.4.3 ASE File ASEParser.cpp ParseLV4MeshBonesVertices heap-based overflow (Issue 6024 / Nessus ID 235880)
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as critical. Affected is the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component ASE File Handler. Such manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2025-3159. An attack has to be approached locally. Furthermore, there is an exploit available.
Applying a patch is advised to resolve this issue.