PT-2023-5413 · Autodesk · Autodesk Autocad

CVE-2023-29076

·

Publicado

2023-08-24

·

Atualizado

2023-11-30

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autodesk AutoCAD versions 2023 through 2024
Description The issue is related to a memory corruption vulnerability when parsing certain file types, including SLDASM, MODEL, SAT, and CATPART files. This vulnerability can be exploited to execute arbitrary code in the current process. The vulnerability is caused by the lack of size checking on input data when copying the buffer, which can lead to memory corruption.
Recommendations For Autodesk AutoCAD versions 2023 and 2024, update to a version that includes the fix for this issue to prevent memory corruption and potential code execution. As a temporary workaround, consider restricting the parsing of SLDASM, MODEL, SAT, and CATPART files until a patch is available. Avoid using the vulnerable file parsing functions until the issue is resolved.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06043
CVE-2023-29076
ZDI-23-1432
ZDI-23-1433
ZDI-23-1434
ZDI-23-1435

Produtos afetados

Autodesk Autocad