An integer overflow in the processing of loaded 2D images...
High severity
Unreviewed
Published
Feb 25, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Feb 24, 2022
Published to the GitHub Advisory Database
Feb 25, 2022
Last updated
Jan 27, 2023
An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process when a specially crafted image file is loaded. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.
References