PT-2005-4113 · Blender · Blender

Joxean Koret

·

Published

2005-10-24

·

Updated

2025-01-16

·

CVE-2005-3302

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Blender version 2.36
Description The issue allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call. This occurs in the bvh import.py module.
Recommendations For Blender version 2.36, consider disabling the eval function call in the bvh import.py module as a temporary workaround until a patch is available. Restrict access to the bvh import.py module to minimize the risk of exploitation. Avoid using the eval function with untrusted input from .bvh files until the issue is resolved.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2005-3302
DSA-1039-1

Affected Products

Blender