CVE-2016-9305: Critical severity Autodesk FBX Software Development Kit vulnerability
Published Jan 25, 2017
·Updated
Improper handling in the Autodesk FBX-SDK before 2017.1 of type mismatches and previously deleted objects related to reading and converting malformed FBX format files can allow attackers to gain access to uninitialized pointers.
Affected Software
1 affected component
Autodesk FBX Software Development Kit<=2017.0
Event History
Jan 25, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9305?
CVE-2016-9305 is classified as a high severity vulnerability due to improper handling of type mismatches.
2
How do I fix CVE-2016-9305?
To mitigate CVE-2016-9305, upgrade to Autodesk FBX SDK version 2017.1 or later.
3
What type of attack can be executed using CVE-2016-9305?
Attackers can exploit CVE-2016-9305 to gain access to uninitialized pointers by processing malformed FBX files.
4
Which versions of Autodesk FBX SDK are affected by CVE-2016-9305?
CVE-2016-9305 affects all versions of Autodesk FBX SDK prior to 2017.1.
5
What should users of Autodesk FBX SDK do in light of CVE-2016-9305?
Users of Autodesk FBX SDK should immediately upgrade to version 2017.1 or later to avoid potential exploitation of CVE-2016-9305.