7.8
CVSSv3

CVE-2022-0545

Published: 24/02/2022 Updated: 02/02/2024
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an malicious user to leak sensitive information or achieve code execution in the context of the Blender process when a specially crafted image file is loaded. This flaw affects Blender versions before 2.83.19, 2.93.8 and 3.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

blender blender

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Multiple vulnerabilities have been discovered in various image parsers in Blender, a 3D modeller/ renderer, which may result in denial of service or the execution of arbitrary code if a malformed file is opened For the oldstable distribution (buster), these problems have been fixed in version 279b+dfsg0-7+deb10u1 For the stable distribution (bu ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2799 blender 17:301-6 17:310-1 Unknown Unknown developerblenderorg/T94629 ...