PT-2020-4585 · Adobe · Indesign
Published
2020-10-20
·
Updated
2021-12-10
·
CVE-2020-24421
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe InDesign versions 15.1.2 and earlier
Description
The issue is related to handling malformed .indd files, which can cause a NULL pointer dereference bug, potentially leading to a denial-of-service of the client application. Additionally, it is described as a memory corruption vulnerability due to insecure handling of malicious .indd files, which could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this issue.
Recommendations
For Adobe InDesign versions 15.1.2 and earlier, consider avoiding the use of malicious or malformed .indd files until a patch is available. As a temporary workaround, restrict the handling of .indd files to minimize the risk of exploitation.
Fix
Buffer Overflow
NULL Pointer Dereference
Access of Memory Location After End of Buffer
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Indesign