CVE-2013-3664

Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which triggers an out-of-bounds stack write.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3662.  NOTE: this issue was SPLIT due to different affected products and codebases (ADT1); CVE-2013-7388 has been assigned to the paintlib issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
googlesketchup
6.0:maintenance_6
googlesketchup
7.0:maintenance_1
googlesketchup
7.1
googlesketchup
7.1:maintenance_1
googlesketchup
7.1:maintenance_2
googlesketchup
8.0
googlesketchup
8.0:maintenance_1
googlesketchup
8.0:maintenance_2
googlesketchup
8.0:maintenance_3
googlesketchup
8.0:maintenance_4
trimblesketchup
𝑥
≤ 8.0
𝑥
= Vulnerable software versions