CVE-2005-4470

Heap-based buffer overflow in the get_bhead function in readfile.c in Blender BlenLoader 2.0 through 2.40pre allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .blend file with a negative bhead.len value, which causes less memory to be allocated than expected, possibly due to an integer overflow.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:blender:blenloader:*:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.0:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.04:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.25:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.26:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.27:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.28:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.28a:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.28c:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.30:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.31a:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.32:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.33:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.33a:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.34:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.35:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.37:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.37a:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.39:*:*:*:*:*:*:*
cpe:2.3:a:blender:blenloader:2.40_alpha:*:*:*:*:*:*:*

History

21 Nov 2024, 00:04

Type Values Removed Values Added
References () http://secunia.com/advisories/18176 - Vendor Advisory () http://secunia.com/advisories/18176 - Vendor Advisory
References () http://secunia.com/advisories/18178 - () http://secunia.com/advisories/18178 -
References () http://secunia.com/advisories/18452 - () http://secunia.com/advisories/18452 -
References () http://secunia.com/advisories/19754 - () http://secunia.com/advisories/19754 -
References () http://www.debian.org/security/2006/dsa-1039 - () http://www.debian.org/security/2006/dsa-1039 -
References () http://www.gentoo.org/security/en/glsa/glsa-200601-08.xml - () http://www.gentoo.org/security/en/glsa/glsa-200601-08.xml -
References () http://www.overflow.pl/adv/blenderinteger.txt - Exploit () http://www.overflow.pl/adv/blenderinteger.txt - Exploit
References () http://www.securityfocus.com/archive/1/419907/100/0/threaded - () http://www.securityfocus.com/archive/1/419907/100/0/threaded -
References () http://www.securityfocus.com/bid/15981 - Exploit () http://www.securityfocus.com/bid/15981 - Exploit
References () http://www.vupen.com/english/advisories/2005/3032 - () http://www.vupen.com/english/advisories/2005/3032 -
References () https://usn.ubuntu.com/238-2/ - () https://usn.ubuntu.com/238-2/ -

Information

Published : 2005-12-22 00:03

Updated : 2024-11-21 00:04


NVD link : CVE-2005-4470

Mitre link : CVE-2005-4470

CVE.ORG link : CVE-2005-4470


JSON object : View

Products Affected

blender

  • blenloader