Adobe Photoshop CS2 and CS3 Exploit Warning

Thanks to ZDNet for this post on exploit code that’s been made publically available for a serious security flaw in Photoshop. This flaw could allow attackers to take complete control of your Windows machine, according to an advisory from FrSIRT.

The flaw, rated critical, is caused by buffer overflow errors when handling a malformed “BMP”, “DIB” or “RLE” file.

“This could be exploited by attackers to take complete control of an affected system by tricking a user into opening a specially crafted file using a vulnerable application,” FrSIRT said.

The exploit code, available at Milw0rm.com, has been successfully tested against Windows XP Service Pack 2.

As of now, there are no patches available for these vulnerabilities. Of course always apply the common sense approach, “Don’t open files from sources you don’t trust”.

This entry was posted on Friday, April 27th, 2007.
You can leave a comment, or trackback from your own site.

No Comments Yet

You can be the first to comment!

Leave a comment