« Volver al listado

CVE-2013-7388

Estado: ModificadaAlta (9.3)—

Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to execute arbitrary code via a crafted RLE4-compressed bitmap (BMP). NOTE: this issue was SPLIT from CVE-2013-3664 due to different affected products and codebases (ADT1).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-7388",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-07-01T17:55:03.997",
  "references": [
    {
      "url": "http://blog.binamuse.com/2013/05/multiple-vulnerabilities-on-sketchup.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/53635",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.binamuse.com/advisories/BINA-20130521B.txt",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/60248",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/84723",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://blog.binamuse.com/2013/05/multiple-vulnerabilities-on-sketchup.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/53635",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.binamuse.com/advisories/BINA-20130521B.txt",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/60248",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/84723",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to execute arbitrary code via a crafted RLE4-compressed bitmap (BMP).  NOTE: this issue was SPLIT from CVE-2013-3664 due to different affected products and codebases (ADT1)."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de buffer basado en memoria dinámica en paintlib, utilizado en Trimble SketchUp (anetriormente Google SketchUp) anterior a 2013 (13.0.3689), permite a atacantes remotos ejecutar código arbitrario a través de un mapa de bits RLE4-comprimido (BMP) manipulado. NOTA: este problema fue dividido (SPLIT) de CVE-2013-3664 debido a diferentes productos y bases de códigos afectados (ADT1)."
    }
  ],
  "lastModified": "2026-06-17T00:01:52.840",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:sketchup:6.0:maintenance_6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D0ECBF9-81D6-46E5-B562-2B211759120C"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:7.0:maintenance_1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B418AD1B-67D0-48A1-BADF-6DF7375F28CB"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23ECF522-3F9A-4514-AC7E-95C81068E4F3"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:7.1:maintenance_1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D6AE8EF-BE0E-404C-B134-CD36B6A63828"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:7.1:maintenance_2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0DFA736-4D8B-453C-8652-0104985CB9D1"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7465758-9BF5-4529-91A4-F442C4D1CC6F"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:8.0:maintenance_1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EBE1ED0-CC18-45AE-8761-3E0B304A18C2"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:8.0:maintenance_2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C4860803-6E0F-448B-981C-4A2531F7455C"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:8.0:maintenance_3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F2DB039C-B6A2-44C0-84FF-BDDAEDFEF906"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:8.0:maintenance_4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "739B944B-51C0-460B-B82B-189F04A3BD87"
            },
            {
              "criteria": "cpe:2.3:a:trimble:sketchup:*:maintenance_5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89A70422-04F4-4358-8B2F-860045AFE586",
              "versionEndIncluding": "8.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}