CVE-2008-4863
published 2008-11-01CVE-2008-4863: Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a Trojan horse Python file in the current…
PriorityP418medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.39%
31.7th percentile
Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to an erroneous setting of sys.path by the PySys_SetArgv function.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| blender | blender | — | — |
| blender | blender | >= 0 < 2.46+dfsg-5 | 2.46+dfsg-5 |
| blender | blender | >= 0 < 2.46+dfsg-5 | 2.46+dfsg-5 |
| blender | blender | >= 0 < 2.46+dfsg-5 | 2.46+dfsg-5 |
| debian | blender | < blender 2.46+dfsg-5 (bookworm) | blender 2.46+dfsg-5 (bookworm) |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9LOW
vendor_redhat6.9MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Blender vulnerabilities
vendor_ubuntu·2008-12-22·CVSS 6.8
CVE-2008-1102 [MEDIUM] Blender vulnerabilities
Title: Blender vulnerabilities
Summary: Blender vulnerabilities
It was discovered that Blender did not correctly handle certain malformed
Radiance RGBE images. If a user were tricked into opening a .blend file
containing a specially crafted Radiance RGBE image, an attacker could execute
arbitrary code with the user's privileges. (CVE-2008-1102)
It was discovered that Blender did not properly sanitize the Python search
path. A local attacker could execute arbitrary code by inserting a specially
crafted Python file in the Blender working directory. (CVE-2008-4863)
Instructions: After a standard system upgrade you need to restart Blender to effect
the necessary changes.
Debian
CVE-2008-4863: blender - Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows loca...
vendor_debian·2008·CVSS 6.9
CVE-2008-4863 [MEDIUM] CVE-2008-4863: blender - Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows loca...
Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to an erroneous setting of sys.path by the PySys_SetArgv function.
Scope: local
bookworm: resolved (fixed in 2.46+dfsg-5)
bullseye: resolved (fixed in 2.46+dfsg-5)
sid: resolved (fixed in 2.46+dfsg-5)
trixie: resolved (fixed in 2.46+dfsg-5)
Red Hat
blender: untrusted python modules search path
vendor_redhat·CVSS 6.9
CVE-2008-4863 [MEDIUM] blender: untrusted python modules search path
blender: untrusted python modules search path
Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to an erroneous setting of sys.path by the PySys_SetArgv function.
GHSA
GHSA-9j9h-289m-795w: Untrusted search path vulnerability in BPY_interface in Blender 2
ghsa_unreviewed·2022-05-17
CVE-2008-4863 [MEDIUM] GHSA-9j9h-289m-795w: Untrusted search path vulnerability in BPY_interface in Blender 2
Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to an erroneous setting of sys.path by the PySys_SetArgv function.
OSV
CVE-2008-4863: Untrusted search path vulnerability in BPY_interface in Blender 2
osv·2008-11-01·CVSS 6.9
CVE-2008-4863 [MEDIUM] CVE-2008-4863: Untrusted search path vulnerability in BPY_interface in Blender 2
Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to an erroneous setting of sys.path by the PySys_SetArgv function.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503632http://security.gentoo.org/glsa/glsa-201001-07.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:038http://www.openwall.com/lists/oss-security/2008/10/27/1http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503632http://security.gentoo.org/glsa/glsa-201001-07.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:038http://www.openwall.com/lists/oss-security/2008/10/27/1
2008-11-01
Published