PT-2009-5861 · Autodesk+1 · Autodesk Maya+1

Published

2009-11-24

·

Updated

2018-10-10

·

CVE-2009-3578

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Autodesk Maya versions 8.0 through 2010 Autodesk Maya version 2008 Autodesk Maya version 2009 Alias Wavefront Maya version 6.5 Alias Wavefront Maya version 7.0
Description The issue allows remote attackers to execute arbitrary code via a .ma or .mb file that uses the Maya Embedded Language (MEL) python command or other MEL commands, related to Script Nodes.
Recommendations For Autodesk Maya versions 8.0 through 2010, consider disabling the use of MEL python commands in .ma and .mb files until a fix is available. For Autodesk Maya version 2008, avoid using Script Nodes in .ma and .mb files. For Autodesk Maya version 2009, restrict access to MEL commands to minimize the risk of exploitation. For Alias Wavefront Maya version 6.5, consider disabling the execution of MEL commands in .ma and .mb files. For Alias Wavefront Maya version 7.0, limit the use of Script Nodes to trusted sources.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3578

Affected Products

Alias Wavefront Maya
Autodesk Maya