KLA10725
Code execution vulnerabilities in Aurodesk Design Review
Обновлено: 17/06/2019
Дата обнаружения
28/10/2015
Уровень угрозы
High
Описание

Multiple serious vulnerabilities have been found in Autodesk Design Review. Malicious users can exploit these vulnerabilities to execute arbitrary code.

Below is a complete list of vulnerabilities

  1. Integer overflow can be exploited remotely via a specially designed BMP file;
  2. Buffer overflows can be exploited remotely via a specially designed BMP, FLI, PCX or GIF files.

Technical details

Vulnerability (1) can be triggered via biClrUsed value.

Vulnerability (2) can be triggered via RLE data in BMP or FLI files, encoded scan lines in PCX file or DataSubBlock or GlobalColorTable in GIF file.

Пораженные продукты

Autodesk Design Review versions earlier than 2013 with hotfix 2

Решение

If you use older version you must update to 2013 and install hotfix. If you already use 2013 version — install hotfix
Autodesk Design Review 2013
Autodesk Design Review hotfix

Первичный источник обнаружения
Autodesk hotfix note
Оказываемое влияние
?
ACE 
[?]
Связанные продукты
Autodesk Design Review
CVE-IDS