First published: Mon Oct 24 2005(Updated: )
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Blender | =2.36 | |
Debian Linux | =3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3302 has been classified as a critical vulnerability due to its ability to allow arbitrary code execution.
To fix CVE-2005-3302, upgrade Blender to a version beyond 2.36 where the eval injection vulnerability is patched.
Blender version 2.36 is affected by CVE-2005-3302, which allows for eval injection vulnerabilities.
CVE-2005-3302 can be exploited by attackers to execute arbitrary Python code through a crafted .bvh file.
Yes, CVE-2005-3302 impacts Debian 3.1 users who may use the affected version of Blender.