PT-2006-4242 · Oracle · Autovue Solidmodel Professional Desktop Edition
Published
2006-07-28
·
Updated
2018-10-18
·
CVE-2006-3350
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AutoVue SolidModel Professional Desktop Edition version 19.1 Build 5993
Description
The issue allows user-assisted remote attackers to execute arbitrary code via a long filename in an archive file, specifically in ARJ, RAR, or ZIP archives.
Recommendations
For AutoVue SolidModel Professional Desktop Edition version 19.1 Build 5993, consider avoiding the use of long filenames in archives until a patch is available. As a temporary workaround, restrict the handling of archive files to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Autovue Solidmodel Professional Desktop Edition