454
VMScore

CVE-2022-0546

Published: 24/02/2022 Updated: 07/11/2023
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an malicious user to cause denial of service, memory corruption or potentially code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

blender blender 2.93.8

blender blender 3.0

fedoraproject fedora 34

fedoraproject extra packages for enterprise linux 7.0

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Multiple vulnerabilities have been discovered in various image parsers in Blender, a 3D modeller/ renderer, which may result in denial of service or the execution of arbitrary code if a malformed file is opened For the oldstable distribution (buster), these problems have been fixed in version 279b+dfsg0-7+deb10u1 For the stable distribution (bu ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2799 blender 17:301-6 17:310-1 Unknown Unknown developerblenderorg/T94572 ...