PT-2022-18948 · Blender+1 · Blender+1
Sangjun Park
·
Published
2022-08-16
·
Updated
2022-09-01
·
CVE-2022-2831
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Blender version 3.3.0
Description
A flaw in the software may cause an integer overflow in the
blendthumb extract.cc file, potentially leading to a program crash or memory corruption. Specifically, when a loaded and valid image is crafted to trigger an out-of-bounds read or write when converted to a thumbnail that is flipped vertically, it may cause a crash.Recommendations
For Blender version 3.3.0, consider avoiding the use of the
blendthumb extract.cc function until a patch is available, or refrain from converting crafted images to thumbnails to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Out of bounds Read
Memory Corruption
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blender
Debian