BleepingComputer.com: Adobe Photoshop - New Malicious Png File Vulnerabi

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Adobe Photoshop - New Malicious Png File Vulnerabi

#1 User is offline   harrywaldron 

  • Security Reporter
  • PipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 509
  • Joined: 10-April 04
  • Gender:Male
  • Location:Roanoke, Virginia

  Posted 30 April 2007 - 03:23 PM

A new PNG buffer overflow vulnerability has surfaced ... While this is most likely proof-of-concept, untrusted PNG formats should not be used in Photoshop until this issue is patched.

Adobe Products PNG.8BI PNG File Handling Buffer Overflow
http://secunia.com/advisories/25044/

Quote

Marsu has discovered a vulnerability in various Adobe Products, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error within the PNG.8BI Photoshop Format Plugin when handling PNG files. This can be exploited to cause a stack-based buffer overflow via a specially crafted PNG file. Successful exploitation allows execution of arbitrary code.

The vulnerability is confirmed in Adobe Photoshop CS2 and Adobe Photoshop Elements (Editor) version 5.0 for Windows and reportedly affects Adobe Photoshop CS3.


#2 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,518
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 01 May 2007 - 06:43 AM

Buffer Overflows In Adobe Products
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users