CVE-2010-5105

The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103.
Configurations

Configuration 1 (hide)

cpe:2.3:a:blender:blender:*:*:*:*:*:*:*:*

History

07 Nov 2023, 02:06

Type Values Removed Values Added
Summary The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103. The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103.

13 Feb 2023, 03:21

Type Values Removed Values Added
Summary The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103. The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103.

Information

Published : 2014-04-27 20:55

Updated : 2023-12-10 11:31


NVD link : CVE-2010-5105

Mitre link : CVE-2010-5105

CVE.ORG link : CVE-2010-5105


JSON object : View

Products Affected

blender

  • blender
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')