CVE-2005-4470Improper Restriction of Operations within the Bounds of a Memory Buffer in Blender

6 documents6 sources
Severity
7.5HIGHNVD
EPSS
6.0%
top 9.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22
Latest updateMay 1

Description

Heap-based buffer overflow in the get_bhead function in readfile.c in Blender BlenLoader 2.0 through 2.40pre allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .blend file with a negative bhead.len value, which causes less memory to be allocated than expected, possibly due to an integer overflow.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

NVDblender/blenloader2.40_pre+19
debiandebian/blender< blender 2.40-1 (bookworm)
Debianblender/blender< 2.40-1+2

🔴Vulnerability Details

2
GHSA
GHSA-x3p7-g646-9j92: Heap-based buffer overflow in the get_bhead function in readfile2022-05-01
OSV
CVE-2005-4470: Heap-based buffer overflow in the get_bhead function in readfile2005-12-22

📋Vendor Advisories

2
Ubuntu
Blender vulnerability2006-01-06
Debian
CVE-2005-4470: blender - Heap-based buffer overflow in the get_bhead function in readfile.c in Blender Bl...2005

💬Community

1
Bugzilla
Blender 2.41 is out, CVE-2005-44702005-12-28