Overview
Autodesk Backburner 2016, version 2016.0.0.2150 and earlier, fails to properly check the length of command input which may be leveraged to create a denial of service condition or to execute arbitrary code.
Description
CWE-121: Stack-based Buffer Overflow - CVE-2016-2344 The Autodesk Knowledge Network describes Backburner as network-rendering management software that supports Autodesk products. The Backburner Manager process listens on TCP/UDP port 3234 by default, though the user may configure the application to use another port. Also note that the process listens on other ports, which may also expose the vulnerability. There is no authentication scheme to restrict access to the service, and the length of command input is not checked. An unauthenticated attacker may directly send specially crafted commands to the interface to overflow the stack buffer, which may be leveraged to crash the service or to gain arbitrary code execution in the context of the user who started the service. Since the software by design permits unauthenticated users to execute arbitrary commands using the cmdjob utility (refer to CVE-2007-4749), the CVSS score below only accounts for exploitation to achieve denial of service. |
Impact
A remote, unauthenticated attacker can execute arbitrary code and create a denial of service condition in Backburner 2016. |
Solution
The CERT/CC is currently unaware of a practical solution to this problem and recommends the following workaround. |
Restrict access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 7.8 | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Temporal | 7.4 | E:F/RL:U/RC:C |
Environmental | 1.8 | CDP:ND/TD:L/CR:ND/IR:ND/AR:ND |
References
- https://knowledge.autodesk.com/support/3ds-max/troubleshooting/caas/CloudHelp/cloudhelp/2016/ENU/Installation-3DSMax/files/GUID-F6732A30-821C-4547-9FAA-E46BCA13392A-htm.html
- https://cwe.mitre.org/data/definitions/121.html
- https://knowledge.autodesk.com/support/3ds-max/troubleshooting/caas/sfdcarticles/sfdcarticles/Backburner-Network-Port-Configuration.html
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4749
- http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-008.txt
Acknowledgements
Thanks to Alex Ondrick for reporting this vulnerability.
This document was written by Joel Land and Will Dormann.
Other Information
CVE IDs: | CVE-2016-2344 |
Date Public: | 2016-03-28 |
Date First Published: | 2016-03-28 |
Date Last Updated: | 2016-03-28 14:53 UTC |
Document Revision: | 26 |