Check Point Reference: | CPAI-2013-2748 |
Date Published: | 10 Dec 2013 |
Severity: | Medium |
Last Updated: | Thursday 02 January, 2025 |
Source: | CVE-2013-3663 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | Trimble Navigation SketchUp 8.x prior to M3 |
Vulnerability Description | A remote code execution vulnerability has been reported in Trimble Navigation's SketchUp. |
Vulnerability Details | The vulnerability is due to a heap buffer overflow while processing BMP files which contain malicious RLE data. Remote unauthenticated attackers can exploit this vulnerability by enticing a target user to open a malicious BMP file. Successful exploitation could result in arbitrary code execution with the privileges of the logged in user. If exploitation is not successful, the application may terminate abnormally. |
This protection will detect and block attempts to exploit this vulnerability.
In order for the protection to be activated, update your product to the latest update. For information on how to update , go to SBP-2006-05, Protection tab and select the version of your choice.
SmartView Tracker will log the following entries:
Attack Name: Content Protection Violation
Attack Information: Trimble Navigation SketchUp BMP File Code Execution