vendor:
Adobe Audition
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Adobe Audition
Affected Version From: 3.0 (build 7238)
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2011-0614
CPE: a:adobe_systems:audition:3.0
Platforms Tested: Microsoft Windows XP Professional SP3
2009
Adobe Audition 3.0 (build 7283) Session File Handling Buffer Overflow PoC
Adobe Audition suffers from a buffer overflow vulnerability when dealing with .SES (session) format file. The application fails to sanitize the user input resulting in a memory corruption, overwriting several memory registers which can aid the attacker to gain the power of executing arbitrary code or denial of service.
Mitigation:
Apply the patch provided by Adobe.