PT-2009-6359 · Adobe · Illustrator Cs3+1
Published
2009-12-04
·
Updated
2018-10-10
·
CVE-2009-4195
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Illustrator CS4 version 14.0.0
Adobe Illustrator CS3 versions 13.0.3 and earlier
Adobe Illustrator CS3 version 13.0.0
Description
The issue allows remote attackers to execute arbitrary code via a long DSC comment in an Encapsulated PostScript (.eps) file.
Recommendations
For Adobe Illustrator CS4 version 14.0.0, update to a version that fixes the buffer overflow issue.
For Adobe Illustrator CS3 versions 13.0.3 and earlier, update to a version that fixes the buffer overflow issue.
For Adobe Illustrator CS3 version 13.0.0, update to a version that fixes the buffer overflow issue.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Illustrator Cs3
Illustrator Cs4