KLA10725
Code execution vulnerabilities in Aurodesk Design Review

Updated: 06/03/2020
Detect date
?
10/28/2015
Severity
?
High
Description

Multiple serious vulnerabilities have been found in Autodesk Design Review. Malicious users can exploit these vulnerabilities to execute arbitrary code.

Below is a complete list of vulnerabilities

  1. Integer overflow can be exploited remotely via a specially designed BMP file;
  2. Buffer overflows can be exploited remotely via a specially designed BMP, FLI, PCX or GIF files.

Technical details

Vulnerability (1) can be triggered via biClrUsed value.

Vulnerability (2) can be triggered via RLE data in BMP or FLI files, encoded scan lines in PCX file or DataSubBlock or GlobalColorTable in GIF file.

Affected products

Autodesk Design Review versions earlier than 2013 with hotfix 2

Solution

If you use older version you must update to 2013 and install hotfix. If you already use 2013 version – install hotfix
Autodesk Design Review 2013
Autodesk Design Review hotfix

Original advisories

Autodesk hotfix note

Impacts
?
ACE 
[?]
Related products
Autodesk Design Review
CVE-IDS
?
Find out the statistics of the vulnerabilities spreading in your region