An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process when a specially crafted image file is loaded. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published: 2022-02-24T18:27:16

Updated: 2024-08-02T23:32:46.403Z

Reserved: 2022-02-08T00:00:00

Link: CVE-2022-0545

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-02-24T19:15:09.760

Modified: 2024-02-02T03:09:18.633

Link: CVE-2022-0545

cve-icon Redhat

No data.