Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35880
HistoryJun 05, 2022 - 3:43 p.m.

Integer Overflow

2022-06-0515:43:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
blender
image processing
vulnerability
code execution

EPSS

0.001

Percentile

50.0%

An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process when a specially crafted image file is loaded. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.