CVE-2017-2902: Buffer Overflow
An exploitable integer overflow exists in the DPX loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.cin' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this exploit?
The vulnerability ID for this exploit is CVE-2017-2902.
What is the severity of CVE-2017-2902?
The severity of CVE-2017-2902 is high with a CVSS score of 7.8.
How does the integer overflow vulnerability in Blender version 2.78c occur?
The integer overflow vulnerability in Blender version 2.78c occurs in the DPX loading functionality when processing a specially crafted '.cin' file.
What can an attacker achieve through this vulnerability?
An attacker can exploit this vulnerability to cause a buffer overflow and potentially execute arbitrary code within the context of the Blender application.
Which versions of Blender and Debian Linux are affected by CVE-2017-2902?
Blender version 2.78c and Debian Linux versions 8.0 and 9.0 are affected by CVE-2017-2902.