Lucene search

K
cveMitreCVE-2005-4470
HistoryDec 22, 2005 - 12:03 a.m.

CVE-2005-4470

2005-12-2200:03:00
mitre
web.nvd.nist.gov
36
cve-2005-4470
buffer overflow
remote attack
denial of service
arbitrary code execution
blender
blenloader

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

High

EPSS

0.022

Percentile

89.6%

Heap-based buffer overflow in the get_bhead function in readfile.c in Blender BlenLoader 2.0 through 2.40pre allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .blend file with a negative bhead.len value, which causes less memory to be allocated than expected, possibly due to an integer overflow.

Affected configurations

Nvd
Node
blenderblenloaderRange2.40_pre
OR
blenderblenloaderMatch2.0
OR
blenderblenloaderMatch2.04
OR
blenderblenloaderMatch2.25
OR
blenderblenloaderMatch2.26
OR
blenderblenloaderMatch2.27
OR
blenderblenloaderMatch2.28
OR
blenderblenloaderMatch2.28a
OR
blenderblenloaderMatch2.28c
OR
blenderblenloaderMatch2.30
OR
blenderblenloaderMatch2.31a
OR
blenderblenloaderMatch2.32
OR
blenderblenloaderMatch2.33
OR
blenderblenloaderMatch2.33a
OR
blenderblenloaderMatch2.34
OR
blenderblenloaderMatch2.35
OR
blenderblenloaderMatch2.37
OR
blenderblenloaderMatch2.37a
OR
blenderblenloaderMatch2.39
OR
blenderblenloaderMatch2.40_alpha
VendorProductVersionCPE
blenderblenloader*cpe:2.3:a:blender:blenloader:*:*:*:*:*:*:*:*
blenderblenloader2.0cpe:2.3:a:blender:blenloader:2.0:*:*:*:*:*:*:*
blenderblenloader2.04cpe:2.3:a:blender:blenloader:2.04:*:*:*:*:*:*:*
blenderblenloader2.25cpe:2.3:a:blender:blenloader:2.25:*:*:*:*:*:*:*
blenderblenloader2.26cpe:2.3:a:blender:blenloader:2.26:*:*:*:*:*:*:*
blenderblenloader2.27cpe:2.3:a:blender:blenloader:2.27:*:*:*:*:*:*:*
blenderblenloader2.28cpe:2.3:a:blender:blenloader:2.28:*:*:*:*:*:*:*
blenderblenloader2.28acpe:2.3:a:blender:blenloader:2.28a:*:*:*:*:*:*:*
blenderblenloader2.28ccpe:2.3:a:blender:blenloader:2.28c:*:*:*:*:*:*:*
blenderblenloader2.30cpe:2.3:a:blender:blenloader:2.30:*:*:*:*:*:*:*
Rows per page:
1-10 of 201

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

High

EPSS

0.022

Percentile

89.6%