CVE-2014-3938: Buffer Overflow
Published Jul 23, 2014
·Updated
Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a PSD file, which triggers a heap-based buffer overflow.
Affected Software
2 affected components
Autodesk SketchBook Pro<=6.2.5
Autodesk SketchBook Pro=6.2.4
Event History
Jul 23, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3938?
CVE-2014-3938 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2014-3938?
To fix CVE-2014-3938, upgrade Autodesk SketchBook Pro to version 6.2.6 or later.
3
What type of attack does CVE-2014-3938 allow?
CVE-2014-3938 allows remote attackers to execute arbitrary code via crafted layer mask data in a PSD file.
4
Which versions of Autodesk SketchBook Pro are affected by CVE-2014-3938?
Versions of Autodesk SketchBook Pro up to and including 6.2.5 are affected by CVE-2014-3938.
5
What is the underlying issue in CVE-2014-3938?
CVE-2014-3938 is caused by an integer overflow that triggers a heap-based buffer overflow.