Bug 239338

Summary: CVE-2007-1253: blender arbitrary python code execution
Product: [Fedora] Fedora Reporter: Ville Skyttä <ville.skytta>
Component: blenderAssignee: Jochen Schmitt <jochen>
Status: CLOSED NEXTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: medium    
Version: 6CC: fedora-security-list
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-05-08 17:09:59 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Ville Skyttä 2007-05-07 17:35:35 UTC
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1253

"Eval injection vulnerability in the (a) kmz_ImportWithMesh.py Script for
Blender 0.1.9h, as used in (b) Blender before 2.43, allows user-assisted remote
attackers to execute arbitrary Python code by importing a crafted (1) KML or (2)
KMZ file."

Comment 1 Jochen Schmitt 2007-05-08 17:09:59 UTC
I have remove the insecure script from the package.