eclipseo / rpms / blender

Forked from rpms/blender 23 days ago
Clone

61424ec Backport e04d7c4 (fix multiple CVEs)

Authored and Committed by music 2 years ago
    Backport e04d7c4 (fix multiple CVEs)
    
        Fix buffer overflow vulnerabilities in mesh code.
    
        Solves these security issues from T52924:
        CVE-2017-12081
        CVE-2017-12082
        CVE-2017-12086
        CVE-2017-12099
        CVE-2017-12100
        CVE-2017-12101
        CVE-2017-12105
    
        While the specific overflow issue may be fixed, loading the repro .blend
        files may still crash because they are incomplete and corrupt. The way
        they crash may be impossible to exploit, but this is difficult to prove.
    
        Differential Revision: https://developer.blender.org/D3002
    
        
file modified
+29 -0