CVE-2022-0546
published 2022-02-24CVE-2022-0546: A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service…
PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.17%
64.2th percentile
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| blender | blender | — | — |
| blender | blender | — | — |
| blender | blender | — | — |
| blender | blender | >= 0 < 2.83.5+dfsg-5+deb11u1 | 2.83.5+dfsg-5+deb11u1 |
| blender | blender | >= 0 < 3.1.2+dfsg-1 | 3.1.2+dfsg-1 |
| blender | blender | >= 0 < 3.1.2+dfsg-1 | 3.1.2+dfsg-1 |
| debian | blender | < blender 3.1.2+dfsg-1 (bookworm) | blender 3.1.2+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv7.8HIGH
cisa9.8CRITICAL
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Adobe Reader and Acrobat Sandbox Bypass Vulnerability
cisa·2022-05-25·CVSS 9.8
CVE-2014-0546 [CRITICAL] Adobe Reader and Acrobat Sandbox Bypass Vulnerability
Vulnerability: Adobe Reader and Acrobat Sandbox Bypass Vulnerability
Affected: Adobe Reader and Acrobat
Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-0546
Remediation Due Date: 2022-06-15
Debian
CVE-2022-0546: blender - A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads ...
vendor_debian·2022·CVSS 7.8
CVE-2022-0546 [HIGH] CVE-2022-0546: blender - A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads ...
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
Scope: local
bookworm: resolved (fixed in 3.1.2+dfsg-1)
bullseye: resolved (fixed in 2.83.5+dfsg-5+deb11u1)
sid: resolved (fixed in 3.1.2+dfsg-1)
trixie: resolved (fixed in 3.1.2+dfsg-1)
GHSA
GHSA-f79h-m9jv-898j: A missing bounds check in the image loader used in Blender 3
ghsa_unreviewed·2022-02-25
CVE-2022-0546 [HIGH] CWE-190 GHSA-f79h-m9jv-898j: A missing bounds check in the image loader used in Blender 3
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
OSV
CVE-2022-0546: A missing bounds check in the image loader used in Blender 3
osv·2022-02-24·CVSS 7.8
CVE-2022-0546 [HIGH] CVE-2022-0546: A missing bounds check in the image loader used in Blender 3
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://developer.blender.org/T94572https://lists.debian.org/debian-lts-announce/2022/06/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIZADV3AHTWZ2YKEFTVLNK3K4F4KTYLM/https://www.debian.org/security/2022/dsa-5176https://developer.blender.org/T94572https://lists.debian.org/debian-lts-announce/2022/06/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIZADV3AHTWZ2YKEFTVLNK3K4F4KTYLM/https://www.debian.org/security/2022/dsa-5176
2022-02-24
Published