<title>Blender: Multiple vulnerabilities</title>
Multiple vulnerabilities in Blender might result in the remote execution of
arbitrary code.
<product type="ebuild">blender</product>
<announced>May 12, 2008</announced>
<revised>May 12, 2008: 01</revised>
<package name="media-gfx/blender" auto="yes" arch="*">
<unaffected range="ge">2.43-r2</unaffected>
<vulnerable range="lt">2.43-r2</vulnerable>
Blender is a 3D creation, animation and publishing program.
Stefan Cornelius (Secunia Research) reported a boundary error within
the imb_loadhdr() function in in the file
source/blender/imbuf/intern/radiance_hdr.c when processing RGBE images
(CVE-2008-1102). Multiple vulnerabilities involving insecure usage of
temporary files have also been reported (CVE-2008-1103).
<impact type="normal">
A remote attacker could entice a user to open a specially crafted file
(.hdr or .blend), possibly resulting in the remote execution of
arbitrary code with the privileges of the user running the application.
There is no known workaround at this time.
All Blender users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=media-gfx/blender-2.43-r2&quot;</code>
<uri link="">CVE-2008-1102</uri>
<uri link="">CVE-2008-1103</uri>
<metadata tag="requester" timestamp="Sun, 11 May 2008 13:10:27 +0000">
<metadata tag="submitter" timestamp="Mon, 12 May 2008 11:15:05 +0000">
<metadata tag="bugReady" timestamp="Mon, 12 May 2008 11:15:14 +0000">