LWN.net Logo

blender: insecure temporary files

Package(s):blender CVE #(s):CVE-2012-4410
Created:September 18, 2012 Updated:September 19, 2012
Description: From the Red Hat bugzilla:

An insecure temporary file use flaw was found in the way 'undo save quit' routine of Blender kernel of Blender, a 3D modeling, animation, rendering and post-production software solution, performed management of 'quit.blend' temporary file, used for session recovery purposes. A local attacker could use this flaw to conduct symbolic link attacks, leading to ability to overwrite arbitrary system file, accessible with the privileges of the user running the blender executable.

Alerts:
Fedora FEDORA-2012-13639 2012-09-17
Fedora FEDORA-2012-13665 2012-09-17

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds