CVE-2007-1253
EPSS 3.1%
Description
Eval injection vulnerability in the (a) kmz_ImportWithMesh.py Script for Blender 0.1.9h, as used in (b) Blender before 2.43, allows user-assisted remote attackers to execute arbitrary Python code by importing a crafted (1) KML or (2) KMZ file.
How to fix CVE-2007-1253
To remediate CVE-2007-1253, upgrade the affected package to a fixed version below.
- Debian/blender—upgrade to 2.42a-6 or later
Is CVE-2007-1253 being exploited?
Low — EPSS is 3.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.42a-6