CVE-2013-5365: Buffer Overflow
Published Apr 2, 2014
·Updated
Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition before 2.0.2 allows remote attackers to execute arbitrary code via RLE-compressed channel data in a PSD file.
Affected Software
4 affected components
Autodesk SketchBook<=6.2.4
Autodesk Sketchbook Express<=6.2.4
Autodesk SketchBook for Enterprise 2014<=6.2.4
Autodesk SketchBook Pro<=6.2.4
Remediation
Event History
Apr 2, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·04:05 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-5365?
CVE-2013-5365 is rated as high severity due to its potential to allow remote code execution.
2
How do I fix CVE-2013-5365?
To fix CVE-2013-5365, update Autodesk SketchBook to version 6.25 or higher.
3
What systems are affected by CVE-2013-5365?
CVE-2013-5365 affects Autodesk SketchBook for Enterprise 2014, SketchBook Pro, SketchBook Express, and Copic Edition versions prior to their respective secure updates.
4
What type of vulnerability is CVE-2013-5365?
CVE-2013-5365 is a heap-based buffer overflow vulnerability.
5
Can CVE-2013-5365 be exploited remotely?
Yes, CVE-2013-5365 can be exploited remotely through RLE-compressed channel data in a specially crafted PSD file.