| Vulnerability Name: | CVE-2008-1102 (CCN-41917) | ||||||||||||||||||||
| Assigned: | 2008-04-21 | ||||||||||||||||||||
| Published: | 2008-04-21 | ||||||||||||||||||||
| Updated: | 2017-08-08 | ||||||||||||||||||||
| Summary: | Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image. | ||||||||||||||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
| Vulnerability Type: | CWE-119 | ||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2008-1102 Source: SUSE Type: UNKNOWN SUSE-SR:2008:010 Source: CCN Type: SA29818 Blender "imb_loadhdr()" Buffer Overflow Vulnerability Source: SECUNIA Type: Vendor Advisory 29818 Source: SECUNIA Type: UNKNOWN 29957 Source: SECUNIA Type: UNKNOWN 30097 Source: SECUNIA Type: UNKNOWN 30151 Source: SECUNIA Type: UNKNOWN 30272 Source: CCN Type: Secunia Research 21/04/2008 Blender "imb_loadhdr()" Buffer Overflow Vulnerability Source: MISC Type: Vendor Advisory http://secunia.com/secunia_research/2008-16/advisory/ Source: CCN Type: Blender SVN Respository SVN checkout and usage Source: CCN Type: Blender Web site blender.org - Get Blender Source: DEBIAN Type: UNKNOWN DSA-1567 Source: DEBIAN Type: DSA-1567 blender -- buffer overrun Source: CCN Type: GLSA-200805-12 Blender: Multiple vulnerabilities Source: GENTOO Type: UNKNOWN GLSA-200805-12 Source: MANDRIVA Type: UNKNOWN MDVSA-2008:204 Source: CCN Type: OSVDB ID: 44464 Blender imb_loadhdr Function Crafted Radiance RGBE Image Handling Remote Overflow Source: BID Type: UNKNOWN 28870 Source: CCN Type: BID-28870 Blender 'radiance_hdr.c' Remote Buffer Overflow Vulnerability Source: CCN Type: USN-699-1 Blender vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2008-1308 Source: XF Type: UNKNOWN blender-imbloadhdr-bo(41917) Source: XF Type: UNKNOWN blender-imbloadhdr-bo(41917) Source: FEDORA Type: UNKNOWN FEDORA-2008-3862 Source: FEDORA Type: UNKNOWN FEDORA-2008-3875 Source: SUSE Type: SUSE-SR:2008:010 SUSE Security Summary Report | ||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
| BACK | |||||||||||||||||||||