Lucene search

K
cveFlexeraCVE-2013-5365
HistoryApr 02, 2014 - 4:05 p.m.

CVE-2013-5365

2014-04-0216:05:51
CWE-119
flexera
web.nvd.nist.gov
31
cve-2013-5365
buffer overflow
autodesk sketchbook
enterprise
pro
express
copic edition
psd file
rle compression
remote code execution

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.3

Confidence

Low

EPSS

0.058

Percentile

93.4%

Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition before 2.0.2 allows remote attackers to execute arbitrary code via RLE-compressed channel data in a PSD file.

Affected configurations

Nvd
Node
autodesksketchbookRange≀6.2.4copic
OR
autodesksketchbook_expressRange≀6.2.4
OR
autodesksketchbook_for_enterprise_2014Range≀6.2.4
OR
autodesksketchbook_proRange≀6.2.4
VendorProductVersionCPE
autodesksketchbook*cpe:2.3:a:autodesk:sketchbook:*:*:*:*:copic:*:*:*
autodesksketchbook_express*cpe:2.3:a:autodesk:sketchbook_express:*:*:*:*:*:*:*:*
autodesksketchbook_for_enterprise_2014*cpe:2.3:a:autodesk:sketchbook_for_enterprise_2014:*:*:*:*:*:*:*:*
autodesksketchbook_pro*cpe:2.3:a:autodesk:sketchbook_pro:*:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.3

Confidence

Low

EPSS

0.058

Percentile

93.4%

Related for CVE-2013-5365