漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Blender 3.0.0 - 5.1.2 Out-of-Bounds Read via crafted .blend SDNA block
Vulnerability Description
Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or read adjacent heap memory by supplying a crafted .blend file with a malicious signed short member_index value in the SDNA block. The member_index field is used as an array index into the sdna->members[] array in sdna_expand_names() without bounds validation, allowing any value outside the allocated range to produce an invalid pointer subsequently passed to strlen(), resulting in a SIGSEGV crash or unintended heap memory disclosure.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Vulnerability Type
跨界内存读
Vulnerability Title
Blender 缓冲区错误漏洞
Vulnerability Description
Blender是Blender组织开源的一个三维计算机图形软件。 Blender 3.0.0版本至5.1.2版本存在缓冲区错误漏洞,该漏洞源于SDNA块中的member_index值边界无效,可能导致攻击者通过提供特制的.blend文件触发崩溃或读取相邻堆内存。
CVSS Information
N/A
Vulnerability Type
N/A