Mandriva Linux Security Advisory : blender (MDVSA-2009:038-1)
Medium Nessus Plugin ID 36763
SynopsisThe remote Mandriva Linux host is missing a security update.
DescriptionPython has a variable called sys.path that contains all paths where Python loads modules by using import scripting procedure. A wrong handling of that variable enables local attackers to execute arbitrary code via Python scripting in the current Blender working directory (CVE-2008-4863).
This update provides fix for that vulnerability.
Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers
SolutionUpdate the affected blender package.