CVE-2017-2905
published 2018-04-24CVE-2017-2905: An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.bmp'…
PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.87%
77.0th percentile
An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.bmp' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger this vulnerability.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| blender | blender | — | — |
| blender | blender | — | — |
| blender | blender | >= 0 < 2.79.a+dfsg0-1 | 2.79.a+dfsg0-1 |
| blender | blender | >= 0 < 2.79.a+dfsg0-1 | 2.79.a+dfsg0-1 |
| blender | blender | >= 0 < 2.79.a+dfsg0-1 | 2.79.a+dfsg0-1 |
| debian | blender | < blender 2.79.a+dfsg0-1 (bookworm) | blender 2.79.a+dfsg0-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-2905: blender - An exploitable integer overflow exists in the bmp loading functionality of the B...
vendor_debian·2017·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905: blender - An exploitable integer overflow exists in the bmp loading functionality of the B...
An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.bmp' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.79.a+dfsg0-1)
bullseye: resolved (fixed in 2.79.a+dfsg0-1)
sid: resolved (fixed in 2.79.a+dfsg0-1)
trixie: resolved (fixed in 2.79.a+dfsg0-1)
GHSA
GHSA-9g2h-6x28-96q6: An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2
ghsa_unreviewed·2022-05-13
CVE-2017-2905 [HIGH] CWE-190 GHSA-9g2h-6x28-96q6: An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2
An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.bmp' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger this vulnerability.
OSV
CVE-2017-2905: An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2
osv·2018-04-24·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905: An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2
An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.bmp' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger this vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2905 blender: Integer Overflow in the upgrade of a legacy Mesh attribute
bugzilla·2018-08-01·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905 blender: Integer Overflow in the upgrade of a legacy Mesh attribute
CVE-2017-2905 blender: Integer Overflow in the upgrade of a legacy Mesh attribute
An exploitable integer overflow exists in the upgrade of a legacy Mesh attribute of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use it as a library in order to trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0433
Discussion:
Created blender tracking bugs for this issue:
Affects: epel-7 [bug 1610865]
Bugzilla
CVE-2017-2905 blender: Integer Overflow in the animation playing functionality
bugzilla·2018-08-01·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905 blender: Integer Overflow in the animation playing functionality
CVE-2017-2905 blender: Integer Overflow in the animation playing functionality
An exploitable integer overflow exists in the animation playing functionality of the Blender open-source 3d creation suite version 2.78c. A specially created '.avi' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset in order to trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0413
Discussion:
Created blender tracking bugs for this issue:
Affects: epel-7 [bug 1610832]
Bugzilla
CVE-2017-2905 blender: Integer Overflow in the multires_load_old_dm functionality
bugzilla·2018-08-01·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905 blender: Integer Overflow in the multires_load_old_dm functionality
CVE-2017-2905 blender: Integer Overflow in the multires_load_old_dm functionality
An exploitable integer overflow exists in the 'multires_load_old_dm' functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open a .blend file in order to trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0452
Discussion:
Created blender tracking bugs for this issue:
Affects: epel-7 [bug 1610858]
Bugzilla
CVE-2017-2905 blender: Integer Overflow in the bmp loading functionality [epel-7]
bugzilla·2018-08-01·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905 blender: Integer Overflow in the bmp loading functionality [epel-7]
CVE-2017-2905 blender: Integer Overflow in the bmp loading functionality [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the '
Bugzilla
CVE-2017-2905 blender: Integer Overflow in the BKE_mesh_vertexCos_get function
bugzilla·2018-08-01·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905 blender: Integer Overflow in the BKE_mesh_vertexCos_get function
CVE-2017-2905 blender: Integer Overflow in the BKE_mesh_vertexCos_get function
An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c applies a particular object modifier to a Mesh. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use the file as a library in order to trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0457
Discussion:
Created blender tracking bugs for this issue:
Affects: epel-7 [bug 1610840]
Bugzilla
CVE-2017-2905 blender: Integer Overflow in the thumbnail functionality
bugzilla·2018-08-01·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905 blender: Integer Overflow in the thumbnail functionality
CVE-2017-2905 blender: Integer Overflow in the thumbnail functionality
An exploitable integer overflow exists in the thumbnail functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to render the thumbnail for the file while in the File->Open dialog.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0415
Discussion:
Created blender tracking bugs for this issue:
Affects: epel-7 [bug 1610836]
Bugzilla
CVE-2017-2905 blender: Integer Overflow in the animation playing functionality
bugzilla·2018-08-01·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905 blender: Integer Overflow in the animation playing functionality
CVE-2017-2905 blender: Integer Overflow in the animation playing functionality
An exploitable integer overflow exists in the animation playing functionality of the Blender open-source 3d creation suite version 2.78c. A specially created '.avi' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset in order to trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0414
Discussion:
Created blender tracking bugs for this issue:
Affects: epel-7 [bug 1610834]
Bugzilla
CVE-2017-2905 blender: Integer Overflow when it draws a Particle object
bugzilla·2018-08-01·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905 blender: Integer Overflow when it draws a Particle object
CVE-2017-2905 blender: Integer Overflow when it draws a Particle object
An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c draws a Particle object. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use the file as a library in order to trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0425
Discussion:
Created blender tracking bugs for this issue:
Affects: epel-7 [bug 1610846]
Bugzilla
CVE-2017-2905 blender: Integer Overflow in the bmp loading functionality
bugzilla·2018-08-01·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905 blender: Integer Overflow in the bmp loading functionality
CVE-2017-2905 blender: Integer Overflow in the bmp loading functionality
An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.bmp' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0412
Discussion:
Created blender tracking bugs for this issue:
Affects: epel-7 [bug 1610829]
Bugzilla
CVE-2017-2905 blender: Integer Overflow in the modifier_mdef_compact_influences functionality
bugzilla·2018-08-01·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905 blender: Integer Overflow in the modifier_mdef_compact_influences functionality
CVE-2017-2905 blender: Integer Overflow in the modifier_mdef_compact_influences functionality
An exploitable integer overflow exists in the 'modifier_mdef_compact_influences' functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open a .blend file in order to trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0453
Discussion:
Created blender tracking bugs for this issue:
Affects: epel-7 [bug 1610856]
Bugzilla
CVE-2017-2905 blender: Integer Overflow in the legacy Mesh attribute tface
bugzilla·2018-08-01·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905 blender: Integer Overflow in the legacy Mesh attribute tface
CVE-2017-2905 blender: Integer Overflow in the legacy Mesh attribute tface
An exploitable integer overflow exists in the upgrade of the legacy Mesh attribute 'tface' of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use it as a library in order to trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0451
Discussion:
Created blender tracking bugs for this issue:
Affects: epel-7 [bug 1610860]
Bugzilla
CVE-2017-2905 blender: Integer Overflow in the Image loading functionality
bugzilla·2018-08-01·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905 blender: Integer Overflow in the Image loading functionality
CVE-2017-2905 blender: Integer Overflow in the Image loading functionality
An exploitable integer overflow exists in the Image loading functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use it as a library in order to trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0425
Discussion:
Created blender tracking bugs for this issue:
Affects: epel-7 [bug 1610843]
Bugzilla
CVE-2017-2905 blender: Integer Overflow in the CustomData Mesh loading functionality
bugzilla·2018-08-01·CVSS 7.8
CVE-2017-2905 [HIGH] CVE-2017-2905 blender: Integer Overflow in the CustomData Mesh loading functionality
CVE-2017-2905 blender: Integer Overflow in the CustomData Mesh loading functionality
An exploitable integer overflow exists in the 'CustomData' Mesh loading functionality of the Blender open-source 3d creation suite. A .blend file with a specially crafted external data file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to edit an object within a .blend library in their Scene in order to trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0434
Discussion:
Created blender tracking bugs for this issue:
Affects: epel-7 [bug 1610862]
https://lists.debian.org/debian-lts-announce/2018/08/msg00011.htmlhttps://www.debian.org/security/2018/dsa-4248https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0412https://lists.debian.org/debian-lts-announce/2018/08/msg00011.htmlhttps://www.debian.org/security/2018/dsa-4248https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0412
2018-04-24
Published