SB2022041259 - Multiple vulnerabilities in Adobe Photoshop
Published: April 12, 2022 Updated: May 4, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 13 secuirty vulnerabilities.
1) Out-of-bounds write (CVE-ID: CVE-2022-28270)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing PSD files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds write and execute arbitrary code on the target system.
2) Use-after-free (CVE-ID: CVE-2022-28271)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing PDF files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger a use-after-free error and execute arbitrary code on the target system.
3) Out-of-bounds write (CVE-ID: CVE-2022-28272)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing PSD files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds write and execute arbitrary code on the target system.
4) Out-of-bounds write (CVE-ID: CVE-2022-28273)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing PSD files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds write and execute arbitrary code on the target system.
5) Out-of-bounds read (CVE-ID: CVE-2022-28274)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing PSD files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds read and execute arbitrary code on the target system.
6) Out-of-bounds write (CVE-ID: CVE-2022-28275)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing PSD files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds write and execute arbitrary code on the target system.
7) Out-of-bounds write (CVE-ID: CVE-2022-28276)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing PSD files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds write and execute arbitrary code on the target system.
8) Out-of-bounds write (CVE-ID: CVE-2022-28277)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing PSD files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds write and execute arbitrary code on the target system.
9) Out-of-bounds write (CVE-ID: CVE-2022-28278)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing PSD files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds write and execute arbitrary code on the target system.
10) Use-after-free (CVE-ID: CVE-2022-28279)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing PSD files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger a use-after-free error and execute arbitrary code on the target system.
11) Out-of-bounds write (CVE-ID: CVE-2022-24105)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing PSD files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds write and execute arbitrary code on the target system.
12) Input validation error (CVE-ID: CVE-2022-24098)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a improper input validation when processing PSD files. A remote attacker can create a specially crafted file, trick the victim into opening it and execute arbitrary code on the target system.
13) Out-of-bounds write (CVE-ID: CVE-2022-23205)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing embedded fonts in PSD files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds write and execute arbitrary code on the target system.
Remediation
Install update from vendor's website.