CVE-2009-3850: Code Injection
Published Nov 6, 2009
·Updated
Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA.
Affected Software
4 affected components
Blender blender=2.34
Blender blender=2.35a
Blender blender=2.40
Blender blender=2.49b
Event History
Nov 6, 2009
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3850?
CVE-2009-3850 is considered a critical vulnerability that allows for remote code execution.
2
How do I fix CVE-2009-3850?
To fix CVE-2009-3850, upgrade to a version of Blender that is not affected by this vulnerability.
3
Which versions of Blender are affected by CVE-2009-3850?
CVE-2009-3850 affects Blender versions 2.34, 2.35a, 2.40, and 2.49b.
4
What type of vulnerability is CVE-2009-3850?
CVE-2009-3850 is a remote code execution vulnerability caused by malicious .blend files.
5
Can I prevent CVE-2009-3850 by disabling Python scripts?
Disabling Python scripting may reduce the risk of CVE-2009-3850, but it is best to update to a secure version of Blender.