PT-2019-18560 · Autodesk · Autodesk Autocad+9
Published
2019-04-09
·
Updated
2020-08-24
·
CVE-2019-7359
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Autodesk Advance Steel version 2018
Autodesk AutoCAD version 2018
Autodesk AutoCAD Architecture version 2018
Autodesk AutoCAD Electrical version 2018
Autodesk AutoCAD Map 3D version 2018
Autodesk AutoCAD Mechanical version 2018
Autodesk AutoCAD MEP version 2018
Autodesk AutoCAD P&ID version 2018
Autodesk AutoCAD Plant 3D version 2018
Autodesk AutoCAD LT version 2018
Autodesk Civil 3D version 2018
Description
The issue is related to a heap overflow vulnerability in the AcCellMargin handling code. It can be triggered by a specially crafted DXF file containing too many cell margins, which may cause a heap overflow and potentially result in code execution.
Recommendations
For Autodesk Advance Steel version 2018, update to a fixed version to resolve the issue.
For Autodesk AutoCAD version 2018, update to a fixed version to resolve the issue.
For Autodesk AutoCAD Architecture version 2018, update to a fixed version to resolve the issue.
For Autodesk AutoCAD Electrical version 2018, update to a fixed version to resolve the issue.
For Autodesk AutoCAD Map 3D version 2018, update to a fixed version to resolve the issue.
For Autodesk AutoCAD Mechanical version 2018, update to a fixed version to resolve the issue.
For Autodesk AutoCAD MEP version 2018, update to a fixed version to resolve the issue.
For Autodesk AutoCAD P&ID version 2018, update to a fixed version to resolve the issue.
For Autodesk AutoCAD Plant 3D version 2018, update to a fixed version to resolve the issue.
For Autodesk AutoCAD LT version 2018, update to a fixed version to resolve the issue.
For Autodesk Civil 3D version 2018, update to a fixed version to resolve the issue.
As a temporary workaround, consider avoiding the use of specially crafted DXF files that may trigger the heap overflow vulnerability until a patch is available.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autodesk Advance Steel
Autodesk Autocad
Autodesk Autocad Architecture
Autodesk Autocad Electrical
Autodesk Autocad Mep
Autodesk Autocad Map 3D
Autodesk Autocad Mechanical
Autodesk Autocad P&Id
Autodesk Autocad Plant 3D
Autodesk Civil 3D