CVE-2025-15538 - CERT CVE
ID CVE-2025-15538
Sažetak A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerability is the function Assimp::LWOImporter::FindUVChannels of the file /src/assimp/code/AssetLib/LWO/LWOMaterial.cpp. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. This and similar defects are tracked and handled via issue #6128.
Reference
CVSS
Base: 4.3
Impact: 6.4
Exploitability:3.1
Pristup
VektorSloženostAutentikacija
LOCAL LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL PARTIAL
CVSS vektor AV:L/AC:L/Au:S/C:P/I:P/A:P
Zadnje važnije ažuriranje 18-01-2026 - 23:15
Objavljeno 18-01-2026 - 23:15