CVE-2013-7388
published 2014-07-01CVE-2013-7388: Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to execute…
PriorityP354critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
13.25%
95.9th percentile
Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to execute arbitrary code via a crafted RLE4-compressed bitmap (BMP). NOTE: this issue was SPLIT from CVE-2013-3664 due to different affected products and codebases (ADT1).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sketchup | — | — | |
| sketchup | — | — | |
| sketchup | — | — | |
| sketchup | — | — | |
| trimble | sketchup | <= 8.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hg63-5gfq-wwmc: Trimble SketchUp (formerly Google SketchUp) before 2013 (13
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2013-3664 [CRITICAL] CWE-119 GHSA-hg63-5gfq-wwmc: Trimble SketchUp (formerly Google SketchUp) before 2013 (13
Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which triggers an out-of-bounds stack write. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3662. NOTE: this issue was SPLIT due to different affected products and codebases (ADT1); CVE-2013-7388 has been assigned to the paintlib issue.
GHSA
GHSA-g9gh-84qj-827r: Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2013-7388 [CRITICAL] CWE-119 GHSA-g9gh-84qj-827r: Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13
Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to execute arbitrary code via a crafted RLE4-compressed bitmap (BMP). NOTE: this issue was SPLIT from CVE-2013-3664 due to different affected products and codebases (ADT1).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://blog.binamuse.com/2013/05/multiple-vulnerabilities-on-sketchup.htmlhttp://secunia.com/advisories/53635http://www.binamuse.com/advisories/BINA-20130521B.txthttp://www.securityfocus.com/bid/60248https://exchange.xforce.ibmcloud.com/vulnerabilities/84723http://blog.binamuse.com/2013/05/multiple-vulnerabilities-on-sketchup.htmlhttp://secunia.com/advisories/53635http://www.binamuse.com/advisories/BINA-20130521B.txthttp://www.securityfocus.com/bid/60248https://exchange.xforce.ibmcloud.com/vulnerabilities/84723
2014-07-01
Published