On BNET: Dumb (but funny) career moves
BNET Business Network:
BNET
TechRepublic
ZDNet

April 25th, 2007

Exploit code posted for critical Adobe Photoshop flaw

Posted by Ryan Naraine @ 9:34 am

Categories: Browsers, Data theft, Exploit code, Hackers, Metasploit, Patch Watch, Pen testing, Responsible disclosure, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Adobe Systems Inc., Adobe PhotoShop, Flaw, Ryan Naraine

In Focus » See more posts on: Adobe

Photoshoppers, be careful.

Publicly available exploit code for a serious security flaw in Adobe Photoshop could allow attackers to take complete control of your Windows machine, according to an advisory from FrSIRT.

Adobe logoThe flaw, rated critical, is caused by buffer overflow errors when handling a malformed "BMP", "DIB" or "RLE" file.

"[This could be exploited by attackers to take complete control of an affected system by tricking a user into opening a specially crafted file using a vulnerable application," FrSIRT said.

Affected products include Adobe Photoshop CS2 and Adobe Photoshop CS3.

The exploit code, available at  Milw0rm.com, has been successfully tested against Windows XP Service Pack 2.

Separately, an exploit for an equally serious flaw in Corel Paint Shop Pro is also in circulation.  This also puts users at risk of code execution attacks using rigged .CLP files. 

There are no patches available for these vulnerabilities.  The standard advice applies:  Be careful when opening files from untrusted sources. 

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 13 Talkback(s)
@all
Good thing I run vista. Calc doesn't usurp admin rights, and it requires you to personally verify administrative permissions before so much as wiping your ass =p... (Read the rest)
Posted by: Spiritusindomit@... Posted on: 09/21/07 You are currently: a Guest | | Terms of Use
How can an application  jacarter3 | 04/25/07
This is how.  kraterz | 04/25/07
Workarounds for apps like that  PB_z | 04/26/07
Completely control the machine?  NonZealot | 04/25/07
I was getting ready to slap you silly  Michael Kelly | 04/25/07
Me too  dragosani | 04/25/07
Assuming admin rights for biggest effect  PB_z | 04/25/07
Wow Zealot...  nix_hed | 04/27/07
@all  Spiritusindomit@... | 09/21/07
Better solution...  Stellardyne | 04/25/07
Try running Photoshop in DOS 6.22.  Grayson Peddie | 04/25/07
Yes, there is a Photoshop for DOS.  Big Scoddie | 04/26/07
Good thing that serious Photoshop users...  Big Scoddie | 04/26/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here