CyberRota Analysis
AI-GeneratedThe Open Asset Import Library (Assimp) is vulnerable due to a heap-based buffer overflow in the 3DGS MDL7 Model Parser, specifically within the Assimp::MDLImporter::ReadFaces_3DGS_MDL7 function. This vulnerability can be exploited remotely, potentially allowing attackers to execute arbitrary code. Organizations using Assimp, particularly those handling 3D model imports, should prioritize applying the recommended patch (ee77bb09a42a49843ac85ef64c14d2328b251df1) to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library code/AssetLib/LWO/LWOLoader.h of the component 3DGS MDL7 Model Parser. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This patch is called ee77bb09a42a49843ac85ef64c14d2328b251df1. Applying a patch is advised to resolve this issue.