Gentoo Linux Security Advisory 201311-7 - Multiple vulnerabilities have been found in Blender, the worst of which could allow attackers to execute arbitrary code. Versions less than 2.49b-r2 are affected.
895983cec8d709bd182528490c8480f44f15829aec91e36fe248418bc732dbc2
Mandriva Linux Security Advisory - Stefan Cornelius of Secunia Research reported a boundary error when Blender processed RGBE images which could be used to execute arbitrary code with the privileges of the user running Blender if a specially crafted.hdr or .blend file were opened. As well, multiple vulnerabilities involving insecure usage of temporary files had also been reported. The updated packages have been patched to prevent these issues.
48609fb663e9cc742f93f54881dfaf9d1d8f643be31783d486819229d88c5293
Gentoo Linux Security Advisory GLSA 200805-12 - Stefan Cornelius (Secunia Research) reported a boundary error within the imb_loadhdr() function in in the file source/blender/imbuf/intern/radiance_hdr.c when processing RGBE images (CVE-2008-1102). Multiple vulnerabilities involving insecure usage of temporary files have also been reported (CVE-2008-1103). Versions less than 2.43-r2 are affected.
7339c4b7695b99e7f31eda25563a078be9b132ace9e2484a5ddb3cc5a085392a