CVE-2015-8572
Autodesk Design Review GIF GlobalColorTable Buffer Overflow Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data in a (1) BMP or (2) FLI file, (3) encoded scan lines in a PCX file, or (4) DataSubBlock or (5) GlobalColorTable in a GIF file.
Múltiples desbordamientos de buffer en Autodesk Design Review (ADR) en versiones anteriores a 2013 Hotfix 2 permite a atacantes remotos ejecutar código arbitrario a través de datos RLE manipulados en (1) un archivo BMP o (2) un archivo FLI, (3) líneas de escaneo codificadas en un archivo PCX , o (4) DataSubBlock o (5) GlobalColorTable en un archivo GIF.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Autodesk Design Review. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of GIF files. The issue lies in the failure to handle the case when the GlobalColorTable is present despite not being specified. An attacker could leverage this vulnerability to execute code within the context of the current process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-12-08 CVE Published
- 2015-12-15 CVE Reserved
- 2024-09-16 CVE Updated
- 2024-10-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.zerodayinitiative.com/advisories/ZDI-15-615 | X_refsource_misc | |
http://www.zerodayinitiative.com/advisories/ZDI-15-616 | X_refsource_misc | |
http://www.zerodayinitiative.com/advisories/ZDI-15-618 | X_refsource_misc | |
http://www.zerodayinitiative.com/advisories/ZDI-15-619 | X_refsource_misc | |
http://www.zerodayinitiative.com/advisories/ZDI-15-620 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Autodesk Search vendor "Autodesk" | Design Review Search vendor "Autodesk" for product "Design Review" | 2013 Search vendor "Autodesk" for product "Design Review" and version "2013" | - |
Affected
|