Vulnerability Description
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) .ASL, (2) .ABR, or (3) .GRD file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Photoshop Cs4 | <= 11.0.1 |
Related Weaknesses (CWE)
References
- http://www.adobe.com/support/security/bulletins/apsb10-13.htmlPatchVendor Advisory
- http://www.exploit-db.com/exploits/12751
- http://www.exploit-db.com/exploits/12752
- http://www.exploit-db.com/exploits/12753
- http://www.securityfocus.com/bid/40389Exploit
- http://www.securitytracker.com/id?1024042
- http://www.zeroscience.mk/codes/psbrush_bof.txtExploit
- http://www.zeroscience.mk/codes/psgradient_bof.txtExploit
- http://www.zeroscience.mk/codes/psstyle_bof.txtExploit
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4938.phpExploit
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4939.phpExploit
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4940.phpExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58888
- http://www.adobe.com/support/security/bulletins/apsb10-13.htmlPatchVendor Advisory
- http://www.exploit-db.com/exploits/12751
FAQ
What is CVE-2010-1296?
CVE-2010-1296 is a vulnerability with a CVSS score of 9.3 (HIGH). Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) .ASL, (2) .ABR, or (3) .GRD file.
How severe is CVE-2010-1296?
CVE-2010-1296 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-1296?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Photoshop Cs4.