CVE-2010-0280: Critical severity lib3ds vulnerability
Array index error in Jan Eric Kyprianidis lib3ds 1.x, as used in Google SketchUp 7.x before 7.1 M2, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted structures in a 3DS file, probably related to mesh.c.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0280?
CVE-2010-0280 has a severity rating that indicates a potential risk for denial of service and possible arbitrary code execution.
How do I fix CVE-2010-0280?
To fix CVE-2010-0280, users should update to a patched version of Google SketchUp or lib3ds that addresses this vulnerability.
Which software is affected by CVE-2010-0280?
CVE-2010-0280 affects Jan Eric Kyprianidis lib3ds 1.x and Google SketchUp versions 7.0 to 7.1.
What type of attack does CVE-2010-0280 enable?
CVE-2010-0280 enables remote attackers to execute a denial of service attack or potentially execute arbitrary code.
When was CVE-2010-0280 published?
CVE-2010-0280 was published in January 2010.