| Package: | blender |
| Date: | 2008-06-13 |
| Vulnerable version: | 2.45-1 |
| Unaffected version: | 2.45-2kalgan1 |
| Bug tracker entry: | http://bugs.frugalware.org/task/3039 |
| CVEs: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1102 |
| Description: | Secunia Research has discovered a vulnerability in Blender, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to a boundary error within the "imb_loadhdr()" function in source/blender/imbuf/intern/radiance_hdr.c, which can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into opening a specially crafted Blender (*.blend) file containing a malicious Radiance RGBE image. Successful exploitation allows execution of arbitrary code. |











