Описание
An exploitable integer overflow exists in the 'CustomData' Mesh loading functionality of the Blender open-source 3d creation suite. A .blend file with a specially crafted external data file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to edit an object within a .blend library in their Scene in order to trigger this vulnerability.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | 2.79+dfsg0-1 |
| cosmic | not-affected | 2.79+dfsg0-1 |
| devel | not-affected | 2.79+dfsg0-1 |
| disco | not-affected | 2.79+dfsg0-1 |
| eoan | not-affected | 2.79+dfsg0-1 |
| esm-apps/bionic | not-affected | 2.79+dfsg0-1 |
| esm-apps/focal | not-affected | 2.79+dfsg0-1 |
| esm-apps/jammy | not-affected | 2.79+dfsg0-1 |
| esm-apps/noble | not-affected | 2.79+dfsg0-1 |
Показывать по
EPSS
6.8 Medium
CVSS2
7.8 High
CVSS3
Связанные уязвимости
An exploitable integer overflow exists in the 'CustomData' Mesh loading functionality of the Blender open-source 3d creation suite. A .blend file with a specially crafted external data file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to edit an object within a .blend library in their Scene in order to trigger this vulnerability.
An exploitable integer overflow exists in the 'CustomData' Mesh loadin ...
An exploitable integer overflow exists in the 'CustomData' Mesh loading functionality of the Blender open-source 3d creation suite. A .blend file with a specially crafted external data file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to edit an object within a .blend library in their Scene in order to trigger this vulnerability.
Уязвимость компонента CustomData набора программного обеспечения для создания трехмерной компьютерной графики Blender, позволяющая нарушителю выполнить произвольный код
EPSS
6.8 Medium
CVSS2
7.8 High
CVSS3