HIGH · 9.3

CVE-2010-0280

Array index error in Jan Eric Kyprianidis lib3ds 1.x, as used in Google SketchUp 7.x before 7.1 M2, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitra...

Vulnerability Description

Array index error in Jan Eric Kyprianidis lib3ds 1.x, as used in Google SketchUp 7.x before 7.1 M2, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted structures in a 3DS file, probably related to mesh.c.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Jan Eric KrprianidisLib3Ds1.0
GoogleGoogle Sketchup7.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-0280?

CVE-2010-0280 is a vulnerability with a CVSS score of 9.3 (HIGH). Array index error in Jan Eric Kyprianidis lib3ds 1.x, as used in Google SketchUp 7.x before 7.1 M2, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitra...

How severe is CVE-2010-0280?

CVE-2010-0280 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-0280?

Check the references section above for vendor advisories and patch information. Affected products include: Jan Eric Krprianidis Lib3Ds, Google Google Sketchup.