Vulnerability Description
Google SketchUp before 8.0.14346 (aka 8 Maintenance 3) allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted SKP file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sketchup | <= 8.0 |
Related Weaknesses (CWE)
References
- http://osvdb.org/85570
- http://support.google.com/sketchup/bin/static.py?page=release_notes.cs
- http://technet.microsoft.com/security/msvr/msvr12-015
- http://www.securityfocus.com/bid/55598
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78676
- http://osvdb.org/85570
- http://support.google.com/sketchup/bin/static.py?page=release_notes.cs
- http://technet.microsoft.com/security/msvr/msvr12-015
- http://www.securityfocus.com/bid/55598
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78676
FAQ
What is CVE-2012-4894?
CVE-2012-4894 is a vulnerability with a CVSS score of 9.3 (HIGH). Google SketchUp before 8.0.14346 (aka 8 Maintenance 3) allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted SKP file.
How severe is CVE-2012-4894?
CVE-2012-4894 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4894?
Check the references section above for vendor advisories and patch information. Affected products include: Google Sketchup.