漏洞信息详情
Adobe Photoshop .PNG图像编辑缓冲区溢出漏洞
- CNNVD编号:CNNVD-200704-609
- 危害等级: 超危
- CVE编号:
CVE-2007-2365
- 漏洞类型:
缓冲区溢出
- 发布时间:
2007-04-30
- 威胁类型:
远程
- 更新时间:
2007-05-09
- 厂 商:
adobe - 漏洞来源:
Marsu is credited … -
漏洞简介
Adobe Photoshop CS2和CS3以及Photoshop Elements中存在缓冲区溢出漏洞。用户协助式远程攻击者可以借助一个特制的.PNG文件,执行任意代码。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Adobe Illustrator CS3
Adobe ai_security_update.dmg
http://www.adobe.com/support/security/bulletins/downloads/ai_security_update.dmg
Adobe ai_security_update.zip
http://www.adobe.com/support/security/bulletins/downloads/ai_security_update.zipAdobe GoLive 9
Adobe gl_security_update.dmg
http://www.adobe.com/support/security/bulletins/downloads/gl_security_update.dmg
Adobe gl_security_update.zip
http://www.adobe.com/support/security/bulletins/downloads/gl_security_update.zip
Adobe Photoshop CS3
Adobe patcher_application.dmgCS3 Update for Macintosh
http://download.macromedia.com/pub/security/bulletins/apsb07-13/mac/patcher_application.dmg
Adobe patcher_application.zipCS3 Update for Windows
http://download.macromedia.com/pub/security/bulletins/apsb07-13/win/patcher_application.zip
参考网址
来源: XF
名称: adobe-pngfile-bo(33956)
链接:http://xforce.iss.net/xforce/xfdb/33956
来源: BID
名称: 23698
链接:http://www.securityfocus.com/bid/23698
来源: MILW0RM
名称: 3812
链接:http://www.milw0rm.com/exploits/3812
来源: VUPEN
名称: ADV-2007-3443
链接:http://www.frsirt.com/english/advisories/2007/3443
来源: VUPEN
名称: ADV-2007-3442
链接:http://www.frsirt.com/english/advisories/2007/3442
来源: VUPEN
名称: ADV-2007-1577
链接:http://www.frsirt.com/english/advisories/2007/1577
来源: www.adobe.com
链接:http://www.adobe.com/support/security/bulletins/apsb07-17.html
来源: www.adobe.com
链接:http://www.adobe.com/support/security/bulletins/apsb07-16.html
来源: www.adobe.com
链接:http://www.adobe.com/support/security/bulletins/apsb07-13.html
来源: SECTRACK
名称: 1018792
链接:http://securitytracker.com/id?1018792
来源: SECUNIA
名称: 26864
链接:http://secunia.com/advisories/26864
来源: SECUNIA
名称: 26846
链接:http://secunia.com/advisories/26846
来源: SECUNIA
名称: 25044
链接:http://secunia.com/advisories/25044
来源: OSVDB
名称: 38063
来源: OSVDB
名称: 35465