Back to search
CVE-2022-0544
Published: Feb 24, 2022
Modified: Aug 2, 2024
PUBLISHED
Description
An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.
| Vendor | Product | Versions |
|---|---|---|
n/a | Blender | affected Blender versions prior to 2.83.19, 2.93.8 and 3.1 |
Weaknesses (CWE)
References
https://developer.blender.org/T94661
x_refsource_MISC
[debian-lts-announce] 20220628 [SECURITY] [DLA 3060-1] blender security update
mailing-list
x_refsource_MLIST
DSA-5176
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now