CVE-2010-1296
Adobe Photoshop CS4 Extended 11.0 - '.ASL' File Handling Remote Buffer Overflow (PoC)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
13Exploited in Wild
-Decision
Descriptions
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) .ASL, (2) .ABR, or (3) .GRD file.
Múltiples desbordamiento de búfer en Adobe Photoshop CS4 anterior a v11.0.2 permite a atacantes asistidos por el usuario ejecutar código de su elección a través de un fichero manipulado (1) .ASL, (2) .ABR, o (3) .GRD
Adobe Photoshop CS4 Extended suffers from a buffer overflow vulnerability when dealing with .GRD (gradients) format file. The application fails to sanitize the user input resulting in a memory corruption, overwriting several memory registers which can aid the attacker to gain the power of executing arbitrary code or denial of service. Version CS4 Extended 11.0.0.0 is affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-04-06 CVE Reserved
- 2010-05-26 First Exploit
- 2010-05-27 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id?1024042 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/58888 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/12753 | 2010-05-26 | |
https://www.exploit-db.com/exploits/12751 | 2010-05-26 | |
https://www.exploit-db.com/exploits/12752 | 2010-05-26 | |
http://www.exploit-db.com/exploits/12751 | 2024-08-07 | |
http://www.exploit-db.com/exploits/12752 | 2024-08-07 | |
http://www.exploit-db.com/exploits/12753 | 2024-08-07 | |
http://www.securityfocus.com/bid/40389 | 2024-08-07 | |
http://www.zeroscience.mk/codes/psbrush_bof.txt | 2024-08-07 | |
http://www.zeroscience.mk/codes/psgradient_bof.txt | 2024-08-07 | |
http://www.zeroscience.mk/codes/psstyle_bof.txt | 2024-08-07 | |
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4938.php | 2024-08-07 | |
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4939.php | 2024-08-07 | |
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4940.php | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://www.adobe.com/support/security/bulletins/apsb10-13.html | 2017-08-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Photoshop Cs4 Search vendor "Adobe" for product "Photoshop Cs4" | <= 11.0.1 Search vendor "Adobe" for product "Photoshop Cs4" and version " <= 11.0.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Photoshop Cs4 Search vendor "Adobe" for product "Photoshop Cs4" | 11.0 Search vendor "Adobe" for product "Photoshop Cs4" and version "11.0" | - |
Affected
|