6.8
CVSSv2

CVE-2008-1102

Published: 22/04/2008 Updated: 08/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote malicious users to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image.

Vulnerable Product Search on Vulmon Subscribe to Product

blender blender 2.45

Vendor Advisories

Debian Bug report logs - #477808 blender: CVE-2008-1102 arbitrary code execution via crafted blend file Package: blender; Maintainer for blender is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for blender is src:blender (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Dat ...
It was discovered that Blender did not correctly handle certain malformed Radiance RGBE images If a user were tricked into opening a blend file containing a specially crafted Radiance RGBE image, an attacker could execute arbitrary code with the user’s privileges (CVE-2008-1102) ...
Stefan Cornelius discovered a vulnerability in the Radiance High Dynamic Range (HDR) image parser in Blender, a 3D modelling application The weakness could enable a stack-based buffer overflow and the execution of arbitrary code if a maliciously-crafted HDR file is opened, or if a directory containing such a file is browsed via Blender's image-ope ...