First published: Fri Jun 13 2014(Updated: )
Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 8 Maintenance 3, allows remote attackers to execute arbitrary code via a crafted RLE8 compressed BMP.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trimble SketchUp Pro | <=8.0 | |
Trimble SketchUp Pro | =6.0-maintenance_6 | |
Trimble SketchUp Pro | =7.0-maintenance_1 | |
Trimble SketchUp Pro | =7.1 | |
Trimble SketchUp Pro | =7.1-maintenance_1 | |
Trimble SketchUp Pro | =7.1-maintenance_2 | |
Trimble SketchUp Pro | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3663 is considered a critical vulnerability due to the potential for remote code execution.
To mitigate CVE-2013-3663, users should update to the latest version of Google SketchUp that addresses this vulnerability.
CVE-2013-3663 affects users of Google SketchUp versions 6.0, 7.0, 7.1, and 8.0 before Maintenance 3.
CVE-2013-3663 is classified as a heap-based buffer overflow vulnerability.
Yes, CVE-2013-3663 can be exploited remotely through crafted RLE8 compressed BMP files.