A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
References
Link | Resource |
---|---|
https://developer.blender.org/T94572 | Mitigation Patch Vendor Advisory |
https://lists.debian.org/debian-lts-announce/2022/06/msg00021.html | Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIZADV3AHTWZ2YKEFTVLNK3K4F4KTYLM/ | |
https://www.debian.org/security/2022/dsa-5176 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: fedora
Published: 2022-02-24T18:27:17
Updated: 2022-07-05T10:06:27
Reserved: 2022-02-08T00:00:00
Link: CVE-2022-0546
JSON object: View
NVD Information
Status : Modified
Published: 2022-02-24T19:15:09.807
Modified: 2023-11-07T03:41:22.280
Link: CVE-2022-0546
JSON object: View
Redhat Information
No data.
CWE