<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>168907</bug_id>
          
          <creation_ts>2007-03-01 17:01 0000</creation_ts>
          <short_desc>media-gfx/blender KML/KMZ Import Command Injection Vulnerability</short_desc>
          <delta_ts>2007-05-02 12:06:52 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/24232/</bug_file_loc>
          <status_whiteboard>B2 [glsa] Executioner</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>167694</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>keith@email.arizona.edu</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>graphics@gentoo.org</cc>
    
    <cc>malverian@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>keith@email.arizona.edu</who>
            <bug_when>2007-03-01 17:01:36 0000</bug_when>
            <thetext>Secunia Research has discovered a vulnerability in Blender, which can be exploited by malicious people to compromise a user&apos;s system.

The vulnerability is caused due to the insecure use of the &quot;eval()&quot; function in kmz_ImportWithMesh.py. This can be exploited to execute arbitrary Python commands by tricking a user into importing a specially crafted &quot;*.kml&quot; or &quot;*.kmz&quot; file.

The vulnerability is confirmed in version 2.42a. Prior versions may also be affected.

Solution:
Update to version 2.43, which no longer includes the affected script.


Reproducible: Didn&apos;t try




http://secunia.com/advisories/24232/</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2007-03-01 17:10:11 0000</bug_when>
            <thetext>(In reply to comment #0)
&gt; Solution:
&gt; Update to version 2.43, which no longer includes the affected script.

blender-2.43 is broken (see Bug 167694); not really a solution.
 </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-25 07:25:52 0000</bug_when>
            <thetext>graphics any news on this one?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-04-09 18:47:59 0000</bug_when>
            <thetext>graphics team please advise. If it&apos;s such a mess, then we&apos;ll have to mask it. It&apos;s  about code injection, it&apos;s serious.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lu_zero@gentoo.org</who>
            <bug_when>2007-04-09 18:52:39 0000</bug_when>
            <thetext>I&apos;m adding right now blender, people with amd64 please check it...

(give me 1h to reshape the ebuild...)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-04-11 10:00:18 0000</bug_when>
            <thetext>Luca, any news on this one?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lu_zero@gentoo.org</who>
            <bug_when>2007-04-11 10:58:18 0000</bug_when>
            <thetext>I still need somebody with amd64 to test the ebuild. the ebuild is in portage but masked because of that.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-04-11 11:20:33 0000</bug_when>
            <thetext>Ahh no update to Changelog.

Maybe just call amd64 to test?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lu_zero@gentoo.org</who>
            <bug_when>2007-04-11 11:59:34 0000</bug_when>
            <thetext>Should do. amd64 team please test blender-2.43</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>welp@gentoo.org</who>
            <bug_when>2007-04-12 07:57:32 0000</bug_when>
            <thetext>Tested on amd64 and removed from package.mask</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lu_zero@gentoo.org</who>
            <bug_when>2007-04-12 08:13:49 0000</bug_when>
            <thetext>I guess we could ask for stabilization then ^^</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-04-12 09:18:39 0000</bug_when>
            <thetext>Thx.

Arches please test and mark stable. Target keywords are:
blender-2.43.ebuild:KEYWORDS=&quot;amd64 ppc ppc64 ~sparc x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>welp@gentoo.org</who>
            <bug_when>2007-04-12 10:28:34 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-04-12 11:42:41 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-04-15 18:38:18 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-04-17 17:25:02 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-05-02 12:06:52 0000</bug_when>
            <thetext>GLSA 200704-19</thetext>
          </long_desc>
      
    </bug>

</bugzilla>