CVE-2005-4470
blender - heap-based buffer overflow
EPSS 5.8%
描述
Heap-based buffer overflow in the get_bhead function in readfile.c in Blender BlenLoader 2.0 through 2.40pre allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .blend file with a negative bhead.len value, which causes less memory to be allocated than expected, possibly due to an integer overflow.
如何修補 CVE-2005-4470
要修補 CVE-2005-4470,請將受影響套件升級到下列已修補版本。
- Debian/blender—升級至 2.40-1 或更新版本
- Debian/blender—升級至 2.37a-1.1etch1 或更新版本
CVE-2005-4470 正在被利用嗎?
中等 — EPSS 為 5.8%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 2.40-1
- from 0, < 2.37a-1.1etch1