PT-2019-18561 · Autodesk · Autodesk Autocad+9
Publicado
2019-04-09
·
Atualizado
2019-05-13
·
CVE-2019-7360
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Autodesk Advance Steel version 2018
Autodesk AutoCAD version 2018
Autodesk AutoCAD Architecture version 2018
Autodesk AutoCAD Electrical version 2018
Autodesk AutoCAD Map 3D version 2018
Autodesk AutoCAD Mechanical version 2018
Autodesk AutoCAD MEP version 2018
Autodesk AutoCAD P&ID version 2018
Autodesk AutoCAD Plant 3D version 2018
Autodesk AutoCAD LT version 2018
Autodesk Civil 3D version 2018
Description
The issue is related to an exploitable use-after-free vulnerability in the DXF-parsing functionality. This vulnerability can be triggered by a specially crafted DXF file, potentially resulting in code execution.
Recommendations
For Autodesk Advance Steel version 2018, update to a fixed version if available.
For Autodesk AutoCAD version 2018, update to a fixed version if available.
For Autodesk AutoCAD Architecture version 2018, update to a fixed version if available.
For Autodesk AutoCAD Electrical version 2018, update to a fixed version if available.
For Autodesk AutoCAD Map 3D version 2018, update to a fixed version if available.
For Autodesk AutoCAD Mechanical version 2018, update to a fixed version if available.
For Autodesk AutoCAD MEP version 2018, update to a fixed version if available.
For Autodesk AutoCAD P&ID version 2018, update to a fixed version if available.
For Autodesk AutoCAD Plant 3D version 2018, update to a fixed version if available.
For Autodesk AutoCAD LT version 2018, update to a fixed version if available.
For Autodesk Civil 3D version 2018, update to a fixed version if available.
As a temporary workaround, consider disabling the DXF-parsing functionality until a patch is available.
Correção
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Autodesk Advance Steel
Autodesk Autocad
Autodesk Autocad Architecture
Autodesk Autocad Electrical
Autodesk Autocad Mep
Autodesk Autocad Map 3D
Autodesk Autocad Mechanical
Autodesk Autocad P&Id
Autodesk Autocad Plant 3D
Autodesk Civil 3D