|
Brought to you by:
Suppliers of:
|
|
|
| |
| The Src, Background, PackageXml properties of the Autodesk IDrop ActiveX can be manipulated to trigger a heap use after free condition resulting in arbitrary remote code execution. Other properties may be vulnerable as well. |
| |
Credit:
The information has been provided by Elazar Broad.
|
| |
Vulnerable Systems:
* IDrop.ocx version 17.1.51.160
Vendor response:
"Thank you for taking the time and effort to identify a potential issue with our technology. We do take each and every customer or developer issue seriously and have spent time in reviewing your analysis of our i-drop technology. At this time, we have ceased investment in i-drop technology. It was released over five years ago as a means for developers to leverage their content delivery; we ve made no new investment in this tool and have no current plans to update it in the near future. We ve recorded your issue in our tracking database and will determine its priority if/when we determine new investment is required for this technology.
Thank You Autodesk"
Disclosure Timeline:
06/17/2008 - Vendor notified
03/31/2009 - Vendor final response
04/02/2009 - this advisory
|
|
|
|
|