Debian DSA-1039-1 : blender - several vulnerabilities

high Nessus Plugin ID 22581

Synopsis

The remote Debian host is missing a security-related update.

Description

Several vulnerabilities have been discovered in blender, a very fast and versatile 3D modeller/renderer. The Common Vulnerabilities and Exposures Project identifies the following problems :

- CVE-2005-3302 Joxean Koret discovered that due to missing input validation a provided script is vulnerable to arbitrary command execution.

- CVE-2005-4470 Damian Put discovered a buffer overflow that allows remote attackers to cause a denial of service and possibly execute arbitrary code.

Solution

Upgrade the blender package.

The old stable distribution (woody) is not affected by this problem.

For the stable distribution (sarge) this problem has been fixed in version 2.36-1sarge1.

See Also

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330895

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=344398

https://security-tracker.debian.org/tracker/CVE-2005-3302

https://security-tracker.debian.org/tracker/CVE-2005-4470

http://www.debian.org/security/2006/dsa-1039

Plugin Details

Severity: High

ID: 22581

File Name: debian_DSA-1039.nasl

Version: 1.18

Type: local

Agent: unix

Published: 10/14/2006

Updated: 1/4/2021

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:blender, cpe:/o:debian:debian_linux:3.1

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/24/2006

Vulnerability Publication Date: 9/30/2005

Reference Information

CVE: CVE-2005-3302, CVE-2005-4470

BID: 15981

DSA: 1039