Memory corruption in Adobe DNG Converter - CVE-2016-7856

 

Memory corruption in Adobe DNG Converter - CVE-2016-7856

Published: December 14, 2016


Vulnerability identifier: #VU1300
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7856
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error. A remote attacker can execute arbitrary code on the target system via unknown attack vectors.

Successful exploitation of the vulnerability results in compromise of vulnerable system.


Affected software

Adobe DNG Converter

How to mitigate CVE-2016-7856



External References

Related Security Bulletins