Release date:
Updated on: 2013-07-19
Affected Systems:
Autodesk autoscaling 2013
Autodesk autoscaling 2012
Autodesk autoscaling 2011
Autodesk AutoCAD Civil 3D 2013.x
Autodesk AutoCAD Civil 3D 2012.x
Autodesk AutoCAD Civil 3D 2011.x
Autodesk AutoCAD Architecture 2013
Autodesk AutoCAD Architecture 2012
Autodesk AutoCAD Architecture 2011
Autodesk AutoCAD MEP 2013
Autodesk AutoCAD MEP 2012
Autodesk AutoCAD MEP 2011
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-3665
Autodesk is a vendor of 2D and 3D design, engineering, and entertainment software. It owns well-known software such as "AutoCAD" and "3DS Max.
Multiple Autodesk products have security vulnerabilities when processing DWG files, which can be exploited by malicious users to execute arbitrary code, thus damaging the user system.
<* Source: Joshep J. Cortez Sanchez
Felipe Andres Manzano
Link: http://secunia.com/advisories/54198/
Http://images.autodesk.com/adsk/files/Autodesk_AutoCAD_Code_Execution_Vulnerability_Hotfix_Readme.pdf
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Autodesk
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.autodesk.com.cn/adsk/servlet/index? Id = 9297866 & siteID = 1170359