PT-2015-3023 · Autodesk · Autodesk Design Review

Kdot

·

Publicado

2015-12-08

·

Atualizado

2016-11-28

·

CVE-2015-8571

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Autodesk Design Review versions prior to 2013 Hotfix 2
Description The issue is caused by an integer overflow in Autodesk Design Review. Exploitation of this issue may allow a remote attacker to execute arbitrary code by using a specially crafted biClrUsed value in a BMP file, leading to a buffer overflow.
Recommendations For versions prior to 2013 Hotfix 2, apply the 2013 Hotfix 2 update to resolve the issue. As a temporary workaround, consider restricting the use of BMP files with crafted biClrUsed values until the update is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00228
CVE-2015-8571
ZDI-15-617

Produtos afetados

Autodesk Design Review