OSVDB ID: 76002

Title: Adobe Photoshop Elements Gradient (GRD) File Handling Overflow

Info

Disclosure

Sep 30, 2011

Discovery

Sep 22, 2009

Dates

Exploit

Oct 01, 2011

Solution

Sep 30, 2011

Description

Adobe Photoshop Elements is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially crafted GRD gradient file, a context-dependent attacker can potentially execute arbitrary code..

Classification

Location: Local / Remote, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Upgrade
Exploit: Exploit Public
Disclosure: Vendor Verified, Coordinated Disclosure

Solution

Upgrade to version 10 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Adobe Systems Incorporated

Photoshop Elements

8.0 20090905.r.605812
8.0

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/76002