Adobe Illustrator Malformed AI File Remote Code Execution Vulnerability
BID:31208
Info
Adobe Illustrator Malformed AI File Remote Code Execution Vulnerability
| Bugtraq ID: | 31208 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-3961 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2008 12:00AM |
| Updated: | Sep 16 2008 11:30PM |
| Credit: | Nathan McFeters of Ernst and Young�??s Advanced Security Center |
| Vulnerable: |
Adobe Illustrator CS2 |
| Not Vulnerable: |
Adobe Illustrator CS3 |
Discussion
Adobe Illustrator Malformed AI File Remote Code Execution Vulnerability
Adobe Illustrator is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing an unsuspecting victim to open a malicious AI file.
Successfully exploiting this issue will allow attackers to execute arbitrary code with the privileges of the user running the affected application.
This issue affects only Adobe Illustrator CS2 for Macintosh.
Adobe Illustrator is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing an unsuspecting victim to open a malicious AI file.
Successfully exploiting this issue will allow attackers to execute arbitrary code with the privileges of the user running the affected application.
This issue affects only Adobe Illustrator CS2 for Macintosh.
Exploit / POC
Adobe Illustrator Malformed AI File Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Illustrator Malformed AI File Remote Code Execution Vulnerability
Solution:
The vendor states that Adobe Illustrator CS3 for Macintosh is not vulnerable. Contact the vendor for details on upgrading from CS2.
Solution:
The vendor states that Adobe Illustrator CS3 for Macintosh is not vulnerable. Contact the vendor for details on upgrading from CS2.
References
Adobe Illustrator Malformed AI File Remote Code Execution Vulnerability
References:
References: