« Volver al listado

CVE-2013-3664

Estado: ModificadaAlta (9.3)—

Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which triggers an out-of-bounds stack write. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3662. NOTE: this issue was SPLIT due to different affected products and codebases (ADT1); CVE-2013-7388 has been assigned to the paintlib issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-3664",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-07-01T17:55:03.947",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2013-06/0008.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://blog.binamuse.com/2013/05/multiple-vulnerabilities-on-sketchup.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/53635",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.binamuse.com/advisories/BINA-20130521A.txt",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/60248",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/84723",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2013-06/0008.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://blog.binamuse.com/2013/05/multiple-vulnerabilities-on-sketchup.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/53635",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.binamuse.com/advisories/BINA-20130521A.txt",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/60248",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/84723",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which triggers an out-of-bounds stack write.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3662.  NOTE: this issue was SPLIT due to different affected products and codebases (ADT1); CVE-2013-7388 has been assigned to the paintlib issue."
    },
    {
      "lang": "es",
      "value": "Trimble SketchUp (anteriormente Google SketchUp) anterior a 2013 (13.0.3689) permite a atacantes remotos inyectar código arbitrario a través de una tabla de paleta de color en una textura MAC Pict, lo que provoca una escritura en pila fuera de rango. NOTA: está vulnerabilidad existe debido a una solución incompleta para CVE-2013-3662. NOTA: este problema fue dividido (SPLIT) debido a diferentes productos y bases de códigos afectados (ADT1); CVE-2013-7388 ha sido asignado al problema paintlib."
    }
  ],
  "lastModified": "2026-06-16T23:55:36.360",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:sketchup:6.0:maintenance_6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D0ECBF9-81D6-46E5-B562-2B211759120C"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:7.0:maintenance_1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B418AD1B-67D0-48A1-BADF-6DF7375F28CB"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23ECF522-3F9A-4514-AC7E-95C81068E4F3"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:7.1:maintenance_1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D6AE8EF-BE0E-404C-B134-CD36B6A63828"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:7.1:maintenance_2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0DFA736-4D8B-453C-8652-0104985CB9D1"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7465758-9BF5-4529-91A4-F442C4D1CC6F"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:8.0:maintenance_1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EBE1ED0-CC18-45AE-8761-3E0B304A18C2"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:8.0:maintenance_2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C4860803-6E0F-448B-981C-4A2531F7455C"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:8.0:maintenance_3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F2DB039C-B6A2-44C0-84FF-BDDAEDFEF906"
            },
            {
              "criteria": "cpe:2.3:a:google:sketchup:8.0:maintenance_4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "739B944B-51C0-460B-B82B-189F04A3BD87"
            },
            {
              "criteria": "cpe:2.3:a:trimble:sketchup:*:maintenance_5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89A70422-04F4-4358-8B2F-860045AFE586",
              "versionEndIncluding": "8.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}