First published: Sun Apr 27 2014(Updated: )
The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Blender Blender | <=2.63a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.