Advisory issued for Adobe vulnerability

Share this article:
An advisory was issued today regarding a "highly critical" vulnerability in two software products: Adobe After Effects CS3 and Adobe Photoshop Album Starter Edition 3.x.

The unpatched flaw allows remote attackers to compromise users' computer systems, according to vulnerability tracking firm Secunia.

The vulnerability, discovered by researcher Scott Laurie and posted on Secunia's website, is "due to a boundary error when handling BMP files. This can be exploited to cause a buffer overflow via a BMP file having a malformed header."

It has also been reported, the advisory says, that the vulnerability can be exploited when a storage device, such as a USB drive or camera, is attached to a vulnerable computer.

While the vulnerability is reported in Adobe Photoshop Album Starter Edition 3.2 and Adobe After Effects CS3, other versions of these programs may also be affected.

Adobe Systems confirmed to SCMagazineUS.com today that a security vulnerability has been discovered with Photoshop Album Starter Edition, whereby a malformed bitmap file (.BMP) could cause malicious code to run on a user's machine.

"We are currently investigating this. In the meantime, we suggest steering clear of files in these formats created by unknown/untrusted parties. Because these formats are uncommonly used in Photoshop Album Starter Edition, we don't anticipate this will be a large issue. However, we...will be working on a fix. Stay tuned for more from us on this."

Secunia echoes this suggestion, advising that users of these programs, as they await a patch, do not process untrusted BMP files using the affected applications. Secunia also suggests that users do not connect untrusted storage devices to the local computer.

As for After Effects, Adobe Systems says it is currently investigating the claim.


Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

Email promises free pizza, ensnares victims in Asprox botnet instead

Email promises free pizza, ensnares victims in Asprox ...

Cloudmark came upon an email that offers free pizza, but clicking on the link to get the coupon ends with victims being ensnared in a botnet.

Report: most orgs lacking in response team, policies to address cyber incidents

In its Q3 threat intelligence report, Solutionary learned that 75 percent of organizations it assisted had no response team or policies and procedures to address cyber incidents.

Flash redirect campaign impacts Carnegie Mellon page, leads to Angler EK

Flash redirect campaign impacts Carnegie Mellon page, leads ...

Malwarebytes found that, since early July, thousands of sites had been targeted in the campaign.