CVE-2025-5166 | Open Asset Import Library Assimp 5.4.3 MDC File Parser MDCLoader.cpp InternReadFile pcVerts out-of-bounds (Nessus ID 258004)
A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This impacts the function MDCImporter::InternReadFile of the file assimp/code/AssetLib/MDC/MDCLoader.cpp of the component MDC File Parser. The manipulation of the argument pcVerts leads to out-of-bounds read.
This vulnerability is listed as CVE-2025-5166. The attack must be carried out locally. In addition, an exploit is available.
The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.