PT-2009-5861 · Autodesk+1 · Autodesk Maya+1

Publicado

2009-11-24

·

Atualizado

2018-10-10

·

CVE-2009-3578

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Autodesk Maya versions 8.0 through 2010 Autodesk Maya version 2008 Autodesk Maya version 2009 Alias Wavefront Maya version 6.5 Alias Wavefront Maya version 7.0
Description The issue allows remote attackers to execute arbitrary code via a .ma or .mb file that uses the Maya Embedded Language (MEL) python command or other MEL commands, related to Script Nodes.
Recommendations For Autodesk Maya versions 8.0 through 2010, consider disabling the use of MEL python commands in .ma and .mb files until a fix is available. For Autodesk Maya version 2008, avoid using Script Nodes in .ma and .mb files. For Autodesk Maya version 2009, restrict access to MEL commands to minimize the risk of exploitation. For Alias Wavefront Maya version 6.5, consider disabling the execution of MEL commands in .ma and .mb files. For Alias Wavefront Maya version 7.0, limit the use of Script Nodes to trusted sources.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-3578

Produtos afetados

Alias Wavefront Maya
Autodesk Maya