CVE-2010-5105
Publication date 27 April 2014
Last updated 24 July 2024
Ubuntu priority
The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103.
Status
Package | Ubuntu Release | Status |
---|---|---|
blender | 25.04 plucky |
Needs evaluation
|
24.04 LTS noble |
Needs evaluation
|
|
22.04 LTS jammy |
Needs evaluation
|
|
20.04 LTS focal |
Needs evaluation
|
|
18.04 LTS bionic |
Needs evaluation
|
|
16.04 LTS xenial |
Needs evaluation
|
|
14.04 LTS trusty | Not in release | |
Notes
sbeattie
according to debian report, 2.49.2~dfsg-1 is not affected should be mitigated by yama tmp hardening