New User, Welcome!     Login

3D modeling

[CORE-2009-1209] Google SketchUp 'lib3ds' 3DS Importer Memory Corruption

3. *Vulnerability Description*

Google SketchUp is a 3D modeling program designed for architects, civil
engineers, filmmakers, game developers, and related professions. Google
SketchUp bundles an old version of 'lib3ds', a library used to process
3DS files. This library is being compiled in a way that leads to
improper validation of data when importing 3DS files; this condition can
be exploited by remote attackers to trigger a memory corruption

CORE-2009-0908: Autodesk SoftImage Scene TOC Arbitrary Command Execution

3. *Vulnerability Description*

Autodesk Softimage [2] is a 3D computer graphics application for
producing 3D computer graphics, 3D modeling, and computer animation.
Autodesk Softimage by default saves a .scntoc file along with the
scene content tree. The scene TOC (scene table of contents) is an
XML-based file that contains scene information. When you open a scene
file, Softimage looks for a corresponding scene TOC file and
automatically reads and applies the information it contains. Scene TOC



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!