Adobe Photoshop .PNG图像编辑缓冲区溢出漏洞

漏洞信息详情

Adobe Photoshop .PNG图像编辑缓冲区溢出漏洞

漏洞简介

Adobe Photoshop CS2和CS3以及Photoshop Elements中存在缓冲区溢出漏洞。用户协助式远程攻击者可以借助一个特制的.PNG文件,执行任意代码。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Adobe Illustrator CS3

Adobe ai_security_update.dmg

http://www.adobe.com/support/security/bulletins/downloads/ai_security_update.dmg

Adobe ai_security_update.zip

http://www.adobe.com/support/security/bulletins/downloads/ai_security_update.zipAdobe GoLive 9

Adobe gl_security_update.dmg

http://www.adobe.com/support/security/bulletins/downloads/gl_security_update.dmg

Adobe gl_security_update.zip

http://www.adobe.com/support/security/bulletins/downloads/gl_security_update.zip

Adobe Photoshop CS3

Adobe patcher_application.dmgCS3 Update for Macintosh

http://download.macromedia.com/pub/security/bulletins/apsb07-13/mac/patcher_application.dmg

Adobe patcher_application.zipCS3 Update for Windows

http://download.macromedia.com/pub/security/bulletins/apsb07-13/win/patcher_application.zip

参考网址

来源: XF

名称: adobe-pngfile-bo(33956)

链接:http://xforce.iss.net/xforce/xfdb/33956

来源: BID

名称: 23698

链接:http://www.securityfocus.com/bid/23698

来源: MILW0RM

名称: 3812

链接:http://www.milw0rm.com/exploits/3812

来源: VUPEN

名称: ADV-2007-3443

链接:http://www.frsirt.com/english/advisories/2007/3443

来源: VUPEN

名称: ADV-2007-3442

链接:http://www.frsirt.com/english/advisories/2007/3442

来源: VUPEN

名称: ADV-2007-1577

链接:http://www.frsirt.com/english/advisories/2007/1577

来源: www.adobe.com

链接:http://www.adobe.com/support/security/bulletins/apsb07-17.html

来源: www.adobe.com

链接:http://www.adobe.com/support/security/bulletins/apsb07-16.html

来源: www.adobe.com

链接:http://www.adobe.com/support/security/bulletins/apsb07-13.html

来源: SECTRACK

名称: 1018792

链接:http://securitytracker.com/id?1018792

来源: SECUNIA

名称: 26864

链接:http://secunia.com/advisories/26864

来源: SECUNIA

名称: 26846

链接:http://secunia.com/advisories/26846

来源: SECUNIA

名称: 25044

链接:http://secunia.com/advisories/25044

来源: OSVDB

名称: 38063

链接:http://osvdb.org/38063

来源: OSVDB

名称: 35465

链接:http://osvdb.org/35465

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享