vendor:
Adobe InDesign CS3
by:
Gjoko 'LiquidWorm' Krstic
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Adobe InDesign CS3
Affected Version From: CS3 10.0
Affected Version To: CS3 10.0
Patch Exists: NO
Related CWE: N/A
CPE: a:adobe:indesign:cs3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (English)
2009
Adobe InDesign CS3 INDD File Handling Buffer Overflow Vulnerability
When parsing .indd files to the application, it crashes instantly overwriting memory registers. Depending on the offset, EBP, EDI, EDX and ESI gets overwritten. Pottential vulnerability use is arbitrary code execution and denial of service.
Mitigation:
Adobe has discontinued support for CS3 since CS5 is out.