PT-2022-18948 · Blender+1 · Blender+1

Sangjun Park

·

Published

2022-08-16

·

Updated

2022-09-01

·

CVE-2022-2831

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Blender version 3.3.0
Description A flaw in the software may cause an integer overflow in the blendthumb extract.cc file, potentially leading to a program crash or memory corruption. Specifically, when a loaded and valid image is crafted to trigger an out-of-bounds read or write when converted to a thumbnail that is flipped vertically, it may cause a crash.
Recommendations For Blender version 3.3.0, consider avoiding the use of the blendthumb extract.cc function until a patch is available, or refrain from converting crafted images to thumbnails to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Memory Corruption

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-2831

Affected Products

Blender
Debian