CVE-2011-2478: Code Injection
Published Apr 17, 2012
·Updated
Google SketchUp before 8 does not properly handle edge geometry in SketchUp (aka .SKP) files, which allows remote attackers to execute arbitrary code via a crafted file.
Affected Software
5 affected components
Google SketchUp<=7.1
Google SketchUp=6.0-maintenance_6
Google SketchUp=7.0-maintenance_1
Google SketchUp=7.1
Google SketchUp=7.1-maintenance_1
Event History
Apr 17, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2478?
CVE-2011-2478 is considered a high-severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2011-2478?
To fix CVE-2011-2478, update Google SketchUp to a version later than 8.
3
What does CVE-2011-2478 affect?
CVE-2011-2478 affects various versions of Google SketchUp, specifically versions prior to 8.
4
Can CVE-2011-2478 be exploited remotely?
Yes, CVE-2011-2478 can be exploited remotely through a crafted SketchUp file.
5
What are the risks of not patching CVE-2011-2478?
Not patching CVE-2011-2478 exposes users to the risk of arbitrary code execution by attackers.