cbcvebase.
CVE-2008-4863
published 2008-11-01

CVE-2008-4863: Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a Trojan horse Python file in the current…

PriorityP418medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.39%
31.7th percentile
Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to an erroneous setting of sys.path by the PySys_SetArgv function.

Affected

5 ranges
VendorProductVersion rangeFixed in
blenderblender
blenderblender>= 0 < 2.46+dfsg-52.46+dfsg-5
blenderblender>= 0 < 2.46+dfsg-52.46+dfsg-5
blenderblender>= 0 < 2.46+dfsg-52.46+dfsg-5
debianblender< blender 2.46+dfsg-5 (bookworm)blender 2.46+dfsg-5 (bookworm)

CVSS provenance

nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9LOW
vendor_redhat6.9MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.