VulnerabilityModified
CVE-2010-5105
The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file.
LOW 3.3EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103.
- CVSS 2.0
- 3.3 LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
- EPSS
- 0.34% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- blender/blender
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00047.html
- http://www.openwall.com/lists/oss-security/2012/09/06/3
- http://www.openwall.com/lists/oss-security/2012/09/07/13
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584621
- https://developer.blender.org/T22509
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00047.html
- http://www.openwall.com/lists/oss-security/2012/09/06/3
- http://www.openwall.com/lists/oss-security/2012/09/07/13
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584621
- https://developer.blender.org/T22509
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.