PT-2018-3129 · Blender Foundation+1 · Blender+1
Published
2018-04-24
·
Updated
2022-06-13
·
CVE-2017-2906
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Blender version 2.78c
Description
An integer overflow exists in the animation playing functionality of the Blender open-source 3D creation suite. This issue can be triggered by a specially created '.avi' file, causing an integer overflow that results in a buffer overflow. This buffer overflow can allow for code execution under the context of the application. An attacker can exploit this by convincing a user to use the malicious file as an asset.
Recommendations
For Blender version 2.78c, consider avoiding the use of '.avi' files from untrusted sources until a patch is available. As a temporary workaround, restrict the use of the animation playing functionality with external files to minimize the risk of exploitation.
Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Blender