PT-2005-4113 · Blender · Blender

·

CVE-2005-3302

·

Publicado

2005-10-24

·

Atualizado

2025-01-16

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Blender version 2.36
Description The issue allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call. This occurs in the bvh import.py module.
Recommendations For Blender version 2.36, consider disabling the eval function call in the bvh import.py module as a temporary workaround until a patch is available. Restrict access to the bvh import.py module to minimize the risk of exploitation. Avoid using the eval function with untrusted input from .bvh files until the issue is resolved.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-3302
DSA-1039-1

Produtos afetados

Blender