An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process when a specially crafted image file is loaded. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: fedora
Published: 2022-02-24T18:27:16
Updated: 2024-08-02T23:32:46.403Z
Reserved: 2022-02-08T00:00:00
Link: CVE-2022-0545
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-02-24T19:15:09.760
Modified: 2024-11-21T06:38:53.133
Link: CVE-2022-0545
Redhat
No data.