Package: blender
Version: 2.37a-1.1
Severity: grave
Tags: security
Justification: user security hole

An integer overflow in the header parser for .blend files can potentially
be exploited to execute code through a heap overflow. Please see 
http://www.overflow.pl/adv/blenderinteger.txt for details.

This is CVE-2005-4470.

Cheers,
          Moritz

-- System Information:
Debian Release: 3.1
  APT prefers stable
  APT policy: (990, 'stable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.4.29-vs1.2.10
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to