CVE-2008-1102
published 2008-04-22CVE-2008-1102: Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that…
PriorityP427medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.89%
89.1th percentile
Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| blender | blender | — | — |
| blender | blender | >= 0 < 2.45-5 | 2.45-5 |
| blender | blender | >= 0 < 2.45-5 | 2.45-5 |
| blender | blender | >= 0 < 2.45-5 | 2.45-5 |
| debian | blender | < blender 2.45-5 (bookworm) | blender 2.45-5 (bookworm) |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Blender vulnerabilities
vendor_ubuntu·2008-12-22·CVSS 6.8
CVE-2008-1102 [MEDIUM] Blender vulnerabilities
Title: Blender vulnerabilities
Summary: Blender vulnerabilities
It was discovered that Blender did not correctly handle certain malformed
Radiance RGBE images. If a user were tricked into opening a .blend file
containing a specially crafted Radiance RGBE image, an attacker could execute
arbitrary code with the user's privileges. (CVE-2008-1102)
It was discovered that Blender did not properly sanitize the Python search
path. A local attacker could execute arbitrary code by inserting a specially
crafted Python file in the Blender working directory. (CVE-2008-4863)
Instructions: After a standard system upgrade you need to restart Blender to effect
the necessary changes.
Red Hat
blender: Blender Radiance RGBE Buffer Overflow
vendor_redhat·2008-04-17·CVSS 6.8
CVE-2008-1102 [MEDIUM] blender: Blender Radiance RGBE Buffer Overflow
blender: Blender Radiance RGBE Buffer Overflow
Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image.
Debian
CVE-2008-1102: blender - Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows u...
vendor_debian·2008·CVSS 6.8
CVE-2008-1102 [MEDIUM] CVE-2008-1102: blender - Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows u...
Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image.
Scope: local
bookworm: resolved (fixed in 2.45-5)
bullseye: resolved (fixed in 2.45-5)
sid: resolved (fixed in 2.45-5)
trixie: resolved (fixed in 2.45-5)
GHSA
GHSA-35pm-rxh5-93qj: Stack-based buffer overflow in the imb_loadhdr function in Blender 2
ghsa_unreviewed·2022-05-01
CVE-2008-1102 [MEDIUM] CWE-119 GHSA-35pm-rxh5-93qj: Stack-based buffer overflow in the imb_loadhdr function in Blender 2
Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image.
OSV
CVE-2008-1102: Stack-based buffer overflow in the imb_loadhdr function in Blender 2
osv·2008-04-22·CVSS 6.8
CVE-2008-1102 [MEDIUM] CVE-2008-1102: Stack-based buffer overflow in the imb_loadhdr function in Blender 2
Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00011.htmlhttp://secunia.com/advisories/29818http://secunia.com/advisories/29957http://secunia.com/advisories/30097http://secunia.com/advisories/30151http://secunia.com/advisories/30272http://secunia.com/secunia_research/2008-16/advisory/http://www.debian.org/security/2008/dsa-1567http://www.gentoo.org/security/en/glsa/glsa-200805-12.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:204http://www.securityfocus.com/bid/28870http://www.vupen.com/english/advisories/2008/1308/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41917https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00225.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00237.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00011.htmlhttp://secunia.com/advisories/29818http://secunia.com/advisories/29957http://secunia.com/advisories/30097http://secunia.com/advisories/30151http://secunia.com/advisories/30272http://secunia.com/secunia_research/2008-16/advisory/http://www.debian.org/security/2008/dsa-1567http://www.gentoo.org/security/en/glsa/glsa-200805-12.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:204http://www.securityfocus.com/bid/28870http://www.vupen.com/english/advisories/2008/1308/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41917https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00225.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00237.html
2008-04-22
Published