6.9
CVSSv2

CVE-2008-4863

Published: 01/11/2008 Updated: 15/04/2010
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to an erroneous setting of sys.path by the PySys_SetArgv function.

Vulnerable Product Search on Vulmon Subscribe to Product

blender blender 2.46

Vendor Advisories

Debian Bug report logs - #503632 blender: Python scripts load modules from current directory Package: blender; Maintainer for blender is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for blender is src:blender (PTS, buildd, popcon) Reported by: James Vega <jamessan@debianorg> Date: Mon, ...
It was discovered that Blender did not correctly handle certain malformed Radiance RGBE images If a user were tricked into opening a blend file containing a specially crafted Radiance RGBE image, an attacker could execute arbitrary code with the user’s privileges (CVE-2008-1102) ...