Autodesk SketchBook Pro PSD File Processing Vulnerability
Release date:
Updated on:
Affected Systems:
Autodesk SketchBook Pro <= 6.2.5
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-3938
Autodesk SketchBook Pro is a SketchBook software.
The implementation of Autodesk SketchBook Pro 6.2.6 or earlier has the integer overflow vulnerability. Remote attackers can exploit this vulnerability to trigger heap buffer overflow by using specially crafted layer mask data in the PSD file.
<* Source: Dmitry Janushkevich
Link: http://secunia.com/advisories/58000
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Autodesk
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.autodesk.com/products/sketchbook-pro/overview
This article permanently updates the link address: