CVE-2008-4863

Publication date 1 November 2008

Last updated 24 July 2024


Ubuntu priority

Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to an erroneous setting of sys.path by the PySys_SetArgv function.

Status

Package Ubuntu Release Status
blender 8.10 intrepid
Fixed 2.46+dfsg-4ubuntu0.1
8.04 LTS hardy
Fixed 2.45-4ubuntu1.1
7.10 gutsy
Fixed 2.44-2ubuntu2.1
6.06 LTS dapper
Fixed 2.41-1ubuntu4.1

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
blender

References

Related Ubuntu Security Notices (USN)

    • USN-699-1
    • Blender vulnerabilities
    • 22 December 2008

Other references