CVE-2008-1103
published 2008-04-28CVE-2008-1103: Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues."
PriorityP412medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.34%
26.7th percentile
Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues."
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| blender | blender | <= 2.63a | — |
| blender | blender | >= 0 < 2.40-1 | 2.40-1 |
| blender | blender | >= 0 < 2.40-1 | 2.40-1 |
| blender | blender | >= 0 < 2.40-1 | 2.40-1 |
| debian | blender | < blender 2.40-1 (bookworm) | blender 2.40-1 (bookworm) |
| debian | blender | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9LOW
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2010-5105: blender - The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allo...
vendor_debian·2010·CVSS 6.9
CVE-2010-5105 [MEDIUM] CVE-2010-5105: blender - The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allo...
The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103.
Scope: local
bookworm: open
bullseye: open
sid: open
trixie: open
Debian
CVE-2008-1103: blender - Multiple unspecified vulnerabilities in Blender have unknown impact and attack v...
vendor_debian·2008·CVSS 6.9
CVE-2008-1103 [MEDIUM] CVE-2008-1103: blender - Multiple unspecified vulnerabilities in Blender have unknown impact and attack v...
Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues."
Scope: local
bookworm: resolved (fixed in 2.40-1)
bullseye: resolved (fixed in 2.40-1)
sid: resolved (fixed in 2.40-1)
trixie: resolved (fixed in 2.40-1)
Red Hat
Blender insecure temporary file usage
vendor_redhat·CVSS 6.9
CVE-2008-1103 [MEDIUM] Blender insecure temporary file usage
Blender insecure temporary file usage
Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues."
GHSA
GHSA-6645-m42r-vrq8: The undo save quit routine in the kernel in Blender 2
ghsa_unreviewed·2022-05-17·CVSS 6.9
CVE-2010-5105 [MEDIUM] CWE-59 GHSA-6645-m42r-vrq8: The undo save quit routine in the kernel in Blender 2
The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103.
GHSA
GHSA-7hh3-qcf7-cr5r: Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues
ghsa_unreviewed·2022-05-01
CVE-2008-1103 [MEDIUM] CWE-59 GHSA-7hh3-qcf7-cr5r: Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues
Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues."
OSV
CVE-2010-5105: The undo save quit routine in the kernel in Blender 2
osv·2014-04-27·CVSS 6.9
CVE-2010-5105 [MEDIUM] CVE-2010-5105: The undo save quit routine in the kernel in Blender 2
The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103.
OSV
CVE-2008-1103: Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues
osv·2008-04-28·CVSS 6.9
CVE-2008-1103 [MEDIUM] CVE-2008-1103: Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues
Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-5105 blender: Insecure temporary file use by creating file string in undo save quit Blender kernel routine
bugzilla·2012-09-06·CVSS 6.9
CVE-2010-5105 [MEDIUM] CVE-2010-5105 blender: Insecure temporary file use by creating file string in undo save quit Blender kernel routine
CVE-2010-5105 blender: Insecure temporary file use by creating file string in undo save quit Blender kernel routine
An insecure temporary file use flaw was found in the way 'undo save quit' routine of Blender kernel of Blender, a 3D modeling, animation, rendering and post-production software solution, performed management of 'quit.blend' temporary file, used for session recovery purposes. A local attacker could use this flaw to conduct symbolic link attacks, leading to ability to overwrite arbitrary system file, accessible with the privileges of the user running the blender executable.
Upstream ticket:
[1] https://projects.blender.org/tracker/index.php?func=detail&aid=22509&group_id=9&atid=498
References:
[2] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584621
This seems to be re-o
Bugzilla
CVE-2008-1103 Blender insecure temporary file usage
bugzilla·2008-04-28·CVSS 6.9
CVE-2008-1103 [MEDIUM] CVE-2008-1103 Blender insecure temporary file usage
CVE-2008-1103 Blender insecure temporary file usage
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-1103 to the following vulnerability:
Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues."
References:
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00011.html
http://www.securityfocus.com/bid/28936
Discussion:
Noted in SuSE advisory:
Since we do not think that Blender is not used in security critical settings
with network input data we fixed this problem only for future products.
The temporary file issue is not currently fixed in SuSE packages.
Further details regarding this are covered in Ubuntu and Debian bug reports:
https://bugs.launchpad.net/ubuntu/+source/blender/+bu
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00011.htmlhttp://secunia.com/advisories/29842http://secunia.com/advisories/29957http://secunia.com/advisories/30151http://www.gentoo.org/security/en/glsa/glsa-200805-12.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:204http://www.securityfocus.com/bid/28936https://exchange.xforce.ibmcloud.com/vulnerabilities/42153http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00011.htmlhttp://secunia.com/advisories/29842http://secunia.com/advisories/29957http://secunia.com/advisories/30151http://www.gentoo.org/security/en/glsa/glsa-200805-12.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:204http://www.securityfocus.com/bid/28936https://exchange.xforce.ibmcloud.com/vulnerabilities/42153
2008-04-28
Published