LWN.net Logo

blender: user-assisted remote execution of arbitrary code

Package(s):blender CVE #(s):CVE-2007-1253
Created:April 24, 2007 Updated:April 25, 2007
Description: Stefan Cornelius of Secunia Research discovered an insecure use of the "eval()" function in kmz_ImportWithMesh.py. A remote attacker could entice a user to open a specially crafted Blender file (.kmz or .kml), resulting in the execution of arbitrary Python code with the privileges of the user running Blender.
Alerts:
Gentoo 200704-19 2007-04-23

(Log in to post comments)

blender: user-assisted remote execution of arbitrary code

Posted May 6, 2007 11:19 UTC (Sun) by kreutzm (subscriber, #4700) [Link]

Debian oldstable is not vulnerable (code not present), Debian stable has the fix already included.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds