CVE-2013-5365
Published Apr 2, 2014
Last updated 11 years ago
Overview
- Description
- Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition before 2.0.2 allows remote attackers to execute arbitrary code via RLE-compressed channel data in a PSD file.
- Source
- PSIRT-CNA@flexerasoftware.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-119
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:sketchbook:*:*:*:*:copic:*:*:*", "vulnerable": true, "matchCriteriaId": "4F938C65-33E8-4056-AA94-4E729179CE84", "versionEndIncluding": "6.2.4" }, { "criteria": "cpe:2.3:a:autodesk:sketchbook_express:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1EA4476-4AC3-41C7-B742-70FC3DCA9DC4", "versionEndIncluding": "6.2.4" }, { "criteria": "cpe:2.3:a:autodesk:sketchbook_for_enterprise_2014:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "05D948D0-B0E7-4E97-9FF0-C2579D32F963", "versionEndIncluding": "6.2.4" }, { "criteria": "cpe:2.3:a:autodesk:sketchbook_pro:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FF67C5E1-94D9-4B94-BFEF-96EA15C0A902", "versionEndIncluding": "6.2.4" } ], "operator": "OR" } ] } ]