CVE-2021-27039

A maliciously crafted TIFF and PCX file can be forced to read and write beyond allocated boundaries when parsing the TIFF and PCX file for based overflow. This vulnerability can be exploited to execute arbitrary code.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2011:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2012:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2013:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2017:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2018:*:*:*:*:*:*:*

History

25 Apr 2022, 19:12

Type Values Removed Values Added
CPE cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*
First Time Autodesk autocad
References (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004 - (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004 - Vendor Advisory

18 Apr 2022, 17:15

Type Values Removed Values Added
Summary A maliciously crafted TIFF file in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be forced to read and write beyond allocated boundaries when parsing the TIFF file. This vulnerability can be exploited to execute arbitrary code. A maliciously crafted TIFF and PCX file can be forced to read and write beyond allocated boundaries when parsing the TIFF and PCX file for based overflow. This vulnerability can be exploited to execute arbitrary code.
References
  • {'url': 'https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0003', 'name': 'https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0003', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • {'url': 'https://www.zerodayinitiative.com/advisories/ZDI-22-505/', 'name': 'https://www.zerodayinitiative.com/advisories/ZDI-22-505/', 'tags': [], 'refsource': 'MISC'}
  • (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004 -

11 Mar 2022, 17:15

Type Values Removed Values Added
References
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-22-505/ -

10 Nov 2021, 17:15

Type Values Removed Values Added
Summary A maliciously crafted TIFF file in Autodesk 2018, 2017, 2013, 2012, 2011 can be forced to read and write beyond allocated boundaries when parsing the TIFF file. This vulnerability can be exploited to execute arbitrary code. A maliciously crafted TIFF file in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be forced to read and write beyond allocated boundaries when parsing the TIFF file. This vulnerability can be exploited to execute arbitrary code.

12 Jul 2021, 16:56

Type Values Removed Values Added
CWE CWE-787
CPE cpe:2.3:a:autodesk:design_review:2017:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2012:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2011:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2013:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2018:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
References (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0003 - (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0003 - Vendor Advisory

09 Jul 2021, 15:38

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-09 15:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-27039

Mitre link : CVE-2021-27039

CVE.ORG link : CVE-2021-27039


JSON object : View

Products Affected

autodesk

  • autocad
  • design_review
CWE
CWE-787

Out-of-bounds Write