CVE-2005-4470: Buffer Overflow
Heap-based buffer overflow in the getbhead function in readfile.c in Blender BlenLoader 2.0 through 2.40pre allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .blend file with a negative bhead.len value, which causes less memory to be allocated than expected, possibly due to an integer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4470?
CVE-2005-4470 has a medium severity rating due to its potential for remote code execution and denial of service.
How do I fix CVE-2005-4470?
To fix CVE-2005-4470, upgrade to a version of Blender BlenLoader that is patched and does not contain this vulnerability.
What are the affected versions in CVE-2005-4470?
Versions of Blender BlenLoader from 2.0 to 2.40pre are affected by CVE-2005-4470.
Can CVE-2005-4470 lead to data loss?
While CVE-2005-4470 primarily causes application crashes, it may indirectly lead to data loss under certain circumstances.
Is CVE-2005-4470 exploitable remotely?
Yes, CVE-2005-4470 can be exploited remotely by sending specially crafted .blend files to the target application.