CVE-2017-2903: Buffer Overflow
An exploitable integer overflow exists in the DPX loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.cin' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-2903.
What is the severity of CVE-2017-2903?
The severity of CVE-2017-2903 is high with a severity value of 7.8.
What is the affected software?
The affected software includes Blender open-source 3d creation suite versions 2.78c, 2.79.b+dfsg0-7+deb10u1, 2.83.5+dfsg-5+deb11u1, 3.4.1+dfsg-2, and 3.6.2+dfsg-2.
What is the remedy for the vulnerability?
The remedies for CVE-2017-2903 are to update Blender to versions 2.79.b+dfsg0-7+deb10u1, 2.83.5+dfsg-5+deb11u1, 3.4.1+dfsg-2, or 3.6.2+dfsg-2.
Are there any additional references for CVE-2017-2903?
Yes, you can find additional references for CVE-2017-2903 at the following links: [1] (Git commit), [2] (TALOS intelligence), [3] (Debian security tracker).