A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
2022-02-24T19:15:09.807
2024-11-21T06:38:53.270
Modified
CVSSv3.1: 7.8 (HIGH)
AV:N/AC:H/Au:N/C:P/I:P/A:P
4.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | blender | blender | 2.93.8 | Yes |
Application | blender | blender | 3.0 | Yes |
Application | fedoraproject | extra_packages_for_enterprise_linux | 7.0 | Yes |
Operating System | fedoraproject | fedora | 34 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |