blender: embedded code execution
| Package(s): | blender |
CVE #(s): | CVE-2009-3850
|
| Created: | July 13, 2011 |
Updated: | October 31, 2012 |
| Description: |
Back in 2009, it was reported that arbitrary Python code could be embedded in .blend files; that code would then be executed by the blender application. It is, thus, a remote code execution bug exploitable by a malicious .blend file.
As of this writing, the vulnerability is still not fully fixed upstream; see this analysis by Sebastian Pipping for lots of details. |
| Alerts: |
|