Impact
The function IOStreamBuffer::getNextBlock in the PLY File Handler of the Open Asset Import Library contains a flaw that permits an out‑of‑bounds read. When a maliciously crafted PLY file is parsed, data outside the intended buffer can be read, potentially revealing internal memory contents or causing a crash. The vulnerability does not provide direct code execution but may degrade confidentiality or availability of a system processing such files.
Affected Systems
Vendors affected are the Open Asset Import Library:Assimp up to and including version 6.0.5. Any build of Assimp that includes the susceptible PLY file handler component should be considered vulnerable.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity vulnerability. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The attack is inferred to be remote through delivery of a crafted PLY file, possibly embedded in data processed by the library. Proper safeguards and monitoring of file inputs are recommended to mitigate risk.
OpenCVE Enrichment