PT-2009-5861 · Autodesk+1 · Autodesk Maya+1
Published
2009-11-24
·
Updated
2018-10-10
·
CVE-2009-3578
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Autodesk Maya versions 8.0 through 2010
Autodesk Maya version 2008
Autodesk Maya version 2009
Alias Wavefront Maya version 6.5
Alias Wavefront Maya version 7.0
Description
The issue allows remote attackers to execute arbitrary code via a .ma or .mb file that uses the Maya Embedded Language (MEL) python command or other MEL commands, related to Script Nodes.
Recommendations
For Autodesk Maya versions 8.0 through 2010, consider disabling the use of MEL python commands in .ma and .mb files until a fix is available.
For Autodesk Maya version 2008, avoid using Script Nodes in .ma and .mb files.
For Autodesk Maya version 2009, restrict access to MEL commands to minimize the risk of exploitation.
For Alias Wavefront Maya version 6.5, consider disabling the execution of MEL commands in .ma and .mb files.
For Alias Wavefront Maya version 7.0, limit the use of Script Nodes to trusted sources.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alias Wavefront Maya
Autodesk Maya