eWeek Security Watch
Advertisement
Advertisement
April 22, 2008 10:12 AM

Adobe Issues Warning for Unpatched Photoshop Flaw



Adobe on the Big Bags Adobe has issued a prepatch advisory for a critical vulnerability in Photoshop Album Starter Edition 3.2, its free image-manipulation software product.

The flaw, which affects Windows users, could be exploited to launch code execution attacks if the target is tricked into opening a malicious BMP file.

The vulnerability remains unpatched.

"Adobe categorizes this as a critical issue and recommends that Photoshop Album Starter Edition 3.2 customers exercise caution when receiving unsolicited or suspicious BMP files," the company said.

Adobe's confirmation follows the public release of exploit code detailing buffer overflows in the way the software program parses header images.

According to a post on the Full Disclosure mailing list, the vulnerability is also present in Adobe After Effects CS3 and Adobe Photoshop CS3.

However, Adobe says Photoshop or Photoshop Elements users who have already applied the updates described in Security Bulletin APSB07-13 are not affected.

Secunia rates this as a "highly critical" issue and notes that the vulnerability can also be exploited when a malicious storage device (USB drives, cameras, etc.) is being attached to a vulnerable computer.

* Photo credit: superfem (Creative Commons 2.0).

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/13366

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise