CVE-2025-70067

EUVD-2025-209616
Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
Debian logo
Debian Releases
Debian Product
Codename
assimp
bookworm
no-dsa
bullseye
no-dsa
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
qt5-qt3d
Amazon Linux 2
0:5.15.3-1.amzn2.0.9
fixed
qt5-qt3d-debuginfo
Amazon Linux 2
0:5.15.3-1.amzn2.0.9
fixed
qt5-qt3d-devel
Amazon Linux 2
0:5.15.3-1.amzn2.0.9
fixed
qt5-qt3d-examples
Amazon Linux 2
0:5.15.3-1.amzn2.0.9
fixed