Autodesk Trust Center

Security advisory

Advisories are used to communicate information related to vulnerabilities identified with Autodesk® products and services. This includes any fixes or workarounds that are applicable to the affected product.

Vulnerabilities in the Autodesk FBX Software Development Kit


Autodesk ID: ADSK-SA-2016-001

Product, Service, Component: Autodesk® FBX-SDK

Impact: Code Execution, Denial of Service

Severity: High

Original Publish: 12/05/2016

Last Revised: 12/05/2016

Severity CVSS Score Impact
Low 0.1 - 3.9 A vulnerability where scope and impact of exploitation is restricted and the ability to exploit is extremely difficult.
Medium 4.0 - 6.9 A vulnerability where exploitation is mitigated by factors such as difficulty to exploit, default configuration or ease of identification.
High 7.0 - 8.9 A vulnerability, which if exploited, would directly impact the confidentiality, integrity or availability of user's data or processing resources.
Critical 9.0 - 10 A vulnerability, which if exploited, would allow remote execution of malicious code without user action.

Summary

Applications and Services that utilize the FBX-SDK Ver. 2017.0 or earlier for processing FBX, DXF, DAE and 3DS formatted files can be impacted by vulnerabilities related to improper memory allocation when opening malformed files.

Description

Vulnerabilities were identified when opening malformed FBX, DXF, DAE or 3DS format files via the FBX-SDK library functions. The vulnerabilities can result in the following conditions:

  • Buffer Overflow: access to unallocated memory, potential code execution

  • Return of Unexpected or Uninitialized Pointers: read from or write to unexpected memory locations, resulting in arbitrary functions to be invoked or denial of service state

  • Infinite Loop: uncontrolled consumption of resources or denial of service state

Affected Products

Item: FBX-SDK

Impacted Versions: 2017.0 and earlier

Mitigated Versions: 2017.1

Update Source: FBX SDK 2017.1

 

Item: 3dsMAX

Impacted Versions: 2014-2017

Mitigated Versions: Public: 2017.0.1 Security Fix Subscribers: 2017.1.1 Security Fix 2014-2016: TBD

Update Source: Autodesk Knowledge Network

 

Item: Flame

Impacted Versions: 2014-2017

Mitigated Versions: 2017 SP3, 2017 Ext1 SP2 2014-2016: TBD

Update Source: Autodesk Knowledge Network

 

Item: Flame Assist

Impacted Versions: 2014-2017

Mitigated Versions: 2017 SP3, 2017 Ext1 SP2 2014-2016: TBD

Update Source: Autodesk Knowledge Network

 

Item: Flare

Impacted Versions: 2014-2017

Mitigated Versions: 2017 SP3, 2017 Ext1 SP2 2014-2016: TBD

Update Source: Autodesk Knowledge Network

 

Item: Modflow Adviser

Impacted Versions: 2015-2017

Mitigated Versions: 2017.3 2015-2016: TBD

Update Source: Autodesk Knowledge Network

 

Item: Modflow Synergy

Impacted Versions: 2015-2017

Mitigated Versions: 2017.3 2015-2016: TBD

Update Source: Autodesk Knowledge Network

 

Item: Smoke

Impacted Versions: 2014-2017

Mitigated Versions: 2017 Update 1 2014-2016: TBD

Update Source: Autodesk Knowledge Network

 

Item: FBX Review

Impacted Versions: 1.4 and earlier

Mitigated Versions: 1.4.1

Update Source: Autodesk Knowledge Network

 

Item: Infraworks 360

Impacted Versions: 2015-2016

Mitigated Versions: 2016 Update 2

Update Source: Autodesk Knowledge Network

 

Item: Maya

Impacted Versions: 2014-2017

Mitigated Versions: 2017 Update 2 2017 Security Fix 2014-2016: TBD

Update Source: Autodesk Knowledge Network

 

Item: Maya LT

Impacted Versions: 2014-2017

Mitigated Versions: LT 2017 Update 2 LT 2017 Security Fix 2014-2016: TBD

Update Source: Autodesk Knowledge Network

 

Item: Motion Builder

Impacted Versions: 2014-2017

Mitigated Versions: 2017 Security Fix 2014-2016: TBD

Update Source: Autodesk Knowledge Network

 

Item: Mudbox

Impacted Versions: 2014-2017

Mitigated Versions: 2017 Security Fix 2014-2016: TBD

Update Source: Autodesk Knowledge Network

 

Item: Stingray

Impacted Versions: 1.5 and earlier

Mitigated Versions: 1.6

Update Source: Autodesk Knowledge Network

*Note: Product list table contents subject to change.

Recommendations

Autodesk highly recommends that customers of the affected products obtain and apply the latest Security Fix for their products via the Autodesk Knowledge Network. For 3rd party developers who use the FBX-SDK in their applications or services, Autodesk highly recommends they obtain and apply the latest version of the FBX-SDK from the update source listed above.

Acknowledgements

Microsoft MSRC Vulnerabilities and Mitigations TeamMembers: Nicolas Joly, Gavin Thomas, Wade Winright, Marek Zmyslowski

Related Information

The following CVE’s have been reserved as a result of the remediation activities. Details regarding each CVE are available here: https://cve.mitre.org

  • CVE-2016-9303: FBX File Buffer Overflow | Code Execution/Denial of Service

  • CVE-2016-9305: FBX File Incorrect Address Control | Code Execution

  • CVE-2016-9304: DFX File Buffer Overflow | Code Execution/Denial of Service

  • CVE-2016-9306: DAE File Buffer Overflow | Code Execution

  • CVE-2016-9307: 3DS File Buffer Overflow | Code Execution

Revision History

Revision: 1.0

Date: 12/05/2016

Description: Original published version


Disclaimer

INFORMATION IN THIS DOCUMENT IS PROVIDED “AS IS” IN CONNECTION WITH AUTODESK PRODUCTS. AUTODESK AND/OR ITS RESPECTIVE SUBSIDIARIES, AFFILIATES, SUPPLIERS AND LICENSORS AND ITS AND THEIR DIRECTORS, OFFICERS, EMPLOYEES, AGENTS AND REPRESENTATIVES MAKE NO REPRESENTATIONS ABOUT THE SITE, ANY PRODUCTS AND SERVICES CONTAINED ON THE SITE OR THE SUITABILITY OF THE INFORMATION CONTAINED IN THE MATERIALS, INFORMATION, CONTENT, DOCUMENTS, AND RELATED GRAPHICS PUBLISHED ON THIS SITE FOR ANY PURPOSE. THE SITE, ANY PRODUCTS OR SERVICES (INCLUDING WITHOUT LIMITATION, THIRD PARTY PRODUCTS AND SERVICES) OBTAINED THROUGH THE SITE, AND ALL SUCH INFORMATION, CONTENT, DOCUMENTS, AND RELATED GRAPHICS ARE PROVIDED FOR YOUR USE AT YOUR OWN RISK AND "AS IS" WITHOUT WARRANTY OF ANY KIND. AUTODESK AND/OR ITS RESPECTIVE SUBSIDIARIES, AFFILIATES, SUPPLIERS AND LICENSORS HEREBY DISCLAIM ALL WARRANTIES AND CONDITIONS WITH REGARD TO THIS SITE, SUCH PRODUCTS AND SERVICES AND SUCH INFORMATION, CONTENT, DOCUMENTS, AND RELATED GRAPHICS, INCLUDING ALL IMPLIED WARRANTIES AND CONDITIONS OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.