|
|
| |
|
| |
blender: insecure temporary files
| Package(s): | blender |
CVE #(s): | CVE-2012-4410
|
| Created: | September 18, 2012 |
Updated: | September 19, 2012 |
| Description: |
From the Red Hat bugzilla:
An insecure temporary file use flaw was found in the way 'undo save quit' routine of Blender kernel of Blender, a 3D modeling, animation, rendering and post-production software solution, performed management of 'quit.blend' temporary file, used for session recovery purposes. A local attacker could use this flaw to conduct symbolic link attacks, leading to ability to overwrite arbitrary system file, accessible with the privileges of the user running the blender executable. |
| Alerts: |
|
( Log in to post comments)
|
|
|