CVE-2010-5105
Publication date 27 April 2014
Last updated 4 August 2025
Ubuntu priority
The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103.
Status
Package | Ubuntu Release | Status |
---|---|---|
blender | 25.04 plucky |
Needs evaluation
|
24.04 LTS noble |
Needs evaluation
|
|
22.04 LTS jammy |
Needs evaluation
|
|
20.04 LTS focal |
Needs evaluation
|
|
18.04 LTS bionic |
Needs evaluation
|
|
16.04 LTS xenial |
Needs evaluation
|
|
14.04 LTS trusty | Not in release | |
Notes
sbeattie
according to debian report, 2.49.2~dfsg-1 is not affected should be mitigated by yama tmp hardening