ZeroHour

CVE-2022-0546

CVSS 3.1
7.8 high
EPSS
1%p66
Published
()
Modified
Description

A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.

Vendors
blenderfedoraprojectdebian
Products
blender, extra packages for enterprise linux, fedora, debian linux
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.