Google SketchUp 3DS File Remote Memory Corruption Vulnerability
BID:37708
Info
Google SketchUp 3DS File Remote Memory Corruption Vulnerability
| Bugtraq ID: | 37708 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-0280 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 12 2010 12:00AM |
| Updated: | Apr 13 2015 09:28PM |
| Credit: | Francisco Falcon from Core Security Technologies |
| Vulnerable: |
Google Sketchup 7.0.10247 Google Sketchup 7.6859 Google Sketchup 7.1.6087 Google Sketchup 7.1.4871 Gentoo Linux |
| Not Vulnerable: |
Google Sketchup 7.1.6860 |
Discussion
Google SketchUp 3DS File Remote Memory Corruption Vulnerability
Google SketchUp is prone to a remote memory corruption vulnerability because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may exploit this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Google SketchUp 7.0.10247, 7.1.4871, and 7.1.6087 are vulnerable; other versions may also be affected.
Google SketchUp is prone to a remote memory corruption vulnerability because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may exploit this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Google SketchUp 7.0.10247, 7.1.4871, and 7.1.6087 are vulnerable; other versions may also be affected.
Exploit / POC
Google SketchUp 3DS File Remote Memory Corruption Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Google SketchUp 3DS File Remote Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Google SketchUp 3DS File Remote Memory Corruption Vulnerability
References:
References:
- Google SketchUp Homepage (Google)
- Google SketchUp 'lib3ds' 3DS Importer Memory Corruption (Core Security Technologies)