Memory corruption - CVE-2016-4167
Published: June 19, 2016 / Updated: July 19, 2016
Detailed vulnerability description
The vulnerability allow a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to unspecified error in Adobe DNG SDK. A remote unauthenticated attacker can cause memory corruption via unspecified vectors.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
How to mitigate CVE-2016-4167
Adobe DNG Software Development Kit (SDK) users can download the updated version via the following download page (https://www.adobe.com/support/downloads/dng/dng_sdk.html). To confirm the installed version is the latest available, users can verify that the included ReadMe.txt file has a creation date of Thursday, May 5, 2016.