Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2022.3252 blender security update 5 July 2022 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: blender Publisher: Debian Operating System: Debian GNU/Linux Resolution: Patch/Upgrade CVE Names: CVE-2022-0546 CVE-2022-0545 CVE-2022-0544 Original Bulletin: http://www.debian.org/security/2022/dsa-5176 Comment: CVSS (Max): 7.8 CVE-2022-0546 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) CVSS Source: NVD Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - - ------------------------------------------------------------------------- Debian Security Advisory DSA-5176-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 04, 2022 https://www.debian.org/security/faq - - ------------------------------------------------------------------------- Package : blender CVE ID : CVE-2022-0544 CVE-2022-0545 CVE-2022-0546 Multiple vulnerabilities have been discovered in various image parsers in Blender, a 3D modeller/ renderer, which may result in denial of service of the execution of arbitrary code if a malformed file is opened. For the oldstable distribution (buster), these problems have been fixed in version 2.79.b+dfsg0-7+deb10u1. For the stable distribution (bullseye), these problems have been fixed in version 2.83.5+dfsg-5+deb11u1. We recommend that you upgrade your blender packages. For the detailed security status of blender please refer to its security tracker page at: https://security-tracker.debian.org/tracker/blender Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org - -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmLDOLoACgkQEMKTtsN8 TjZKpxAAlbJc9ntBoEe1fcxqfEfyVyF7ypbCsf+75uBtuGarBORx16P5cunX1fq6 fvIsRaPsaqjKPBRbPFwaWuMtLrtg28vXDvU/X3hil9xzXwlvD1Ljhd6aSLcpTN3s +kHxaTMbm0FJs9Akvol3rGm+3LF7eMDipGZ6BfE7tkcjO+ABNMQzHnVuytCf0p1l pGJJUCCWk23esBMnJpr7ba8pT1GJrSCPxYaNKozwDgA/AwSNPj2eHDh+W3if9ke8 ygo2U+3QrF5NYL4MQhPmqIEYBGCRTE9FT89jTXU8HItAKubvEAZAdXO147nuPgVf Fia7Frpb3loB6UJJHWBRVYh781VnqeQZdAW7iGISZQVHKBMJ29n0gp5lDh6Uxtlx thtxglj9bjjpySvvj7F1iC+R50Inmee9PsJbkf+bjv/prTEc6C+V9ZoAzQyQHr4N dmFCwe5OrCM5EZybH/pj+6HXA/v7XmTshpQv/a1erUVYiRYTO1T9hsSJDvROcI9F rPYR+3OaYRkBB68hYSFIGR5dw3EO81Te96jJkruQUKBSgIz2SM5nQn1BXjJ6NKJu 6IzeEgo+tVeIxD0dvmVE9AcQC5O/BPrIFe+5eaohGdA2uJN0wC3U5YrCYE8J0/OK 0HqEePKuQvLJW3yKwQxpTCtAPyoTfBn7rySE0NctgYsXy1JkELs= =0ETO - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: https://auscert.org.au/gpg-key/ iQIVAwUBYsO0M8kNZI30y1K9AQg3Vg/9FRYf9XyxIQvLqWZwAcV9IyGOwzNsy+mX 0Z7an0a/XofKDghx+iRoI5243YSlKIL4/f121JSHIL6hw9P+kDgXC7IewCKZldmt xzs+/K0/j3Zq4hcdHWbXyugo05ly40oiSf4VzOdRmLVyQPw1nzO2uDtQqELtaO7f ITP7GTKz4nxd3+GKKL9VCbgt580SYwnIyZuuDunKiuqPO7Nxl/mARpH0dgKWoR/W FD1MnbvNc6LY1h6JwLWsoR4pfbC+cmpsOOYqUxa7oFVopscTk4EG5bQRX/epVR6F vlWJHc0RGjDnnXbyTUKzv3JeKyFlga0HFKcgmIneNNHyHP2dlPuGBYPAH98OYmfR R1/KVbRxhXpdptR4FLKVN9yTAR00i7mOEysHj+Gs6r6nHnOBmXnMQ0vXANu+N1S3 5qpR2tAhRhNWqoQPx+bV8wIa3SDOI9/T/K47ETkkj5BKFkH7BoojC2gybrrieEKV PJrRA3ZzoBt4Bemu+zOUZBVI2WU/duHe+QWtnkQP5z1gmypt1ZfwP/OPssfPm/qu FkjNH8Pd04DAM95hzF6p3TPzfTgl8jmu91LDYCNf/7q7iArQiumwbqSTpjmt4RYN e1pLtre5ETeCcT5dK8d5OrNDx/olIiMY58ilWb2zLY5oD+F2/plP+w6fz2dlM1VT S7+nFKIk+RQ= =Q7Qa -----END PGP SIGNATURE-----