Vulnerability Details CVE-2005-4470
Heap-based buffer overflow in the get_bhead function in readfile.c in Blender BlenLoader 2.0 through 2.40pre allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .blend file with a negative bhead.len value, which causes less memory to be allocated than expected, possibly due to an integer overflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.06
EPSS Ranking 90.2%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2005-4470
-
cpe:2.3:a:blender:blenloader:*
-
cpe:2.3:a:blender:blenloader:2.0
-
cpe:2.3:a:blender:blenloader:2.04
-
cpe:2.3:a:blender:blenloader:2.25
-
cpe:2.3:a:blender:blenloader:2.26
-
cpe:2.3:a:blender:blenloader:2.27
-
cpe:2.3:a:blender:blenloader:2.28
-
cpe:2.3:a:blender:blenloader:2.28a
-
cpe:2.3:a:blender:blenloader:2.28c
-
cpe:2.3:a:blender:blenloader:2.30
-
cpe:2.3:a:blender:blenloader:2.31a
-
cpe:2.3:a:blender:blenloader:2.32
-
cpe:2.3:a:blender:blenloader:2.33
-
cpe:2.3:a:blender:blenloader:2.33a
-
cpe:2.3:a:blender:blenloader:2.34
-
cpe:2.3:a:blender:blenloader:2.35
-
cpe:2.3:a:blender:blenloader:2.37
-
cpe:2.3:a:blender:blenloader:2.37a
-
cpe:2.3:a:blender:blenloader:2.39
-
cpe:2.3:a:blender:blenloader:2.40_alpha