PT-2008-6041 · Blender · Blender

Steffen Joeris

·

Publicado

2008-10-31

·

Atualizado

2010-04-15

·

CVE-2008-4863

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Blender version 2.46
Description The issue is related to an untrusted search path vulnerability in the BPY interface of Blender, allowing local users to execute arbitrary code via a Trojan horse Python file in the current working directory. This is due to an erroneous setting of sys.path by the PySys SetArgv function.
Recommendations For Blender version 2.46, consider restricting the execution of Python files from untrusted sources to minimize the risk of exploitation. As a temporary workaround, avoid using the PySys SetArgv function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2008-4863

Produtos afetados

Blender