An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.
2022-02-24T19:15:09.713
2024-11-21T06:38:53.007
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:N/AC:H/Au:N/C:P/I:N/A:N
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | blender | blender | < 2.83.19 | Yes |
Application | blender | blender | < 2.93.8 | Yes |
Application | blender | blender | < 3.1 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |