Adobe dng sdk Memory Corruption Vulnerability (CVE-2016-4167)
Adobe dng sdk Memory Corruption Vulnerability (CVE-2016-4167)
Release date:
Updated on:
Affected Systems:
Adobe DNG Software Development Kit <1.4 2016
Adobe DNG Software Development Kit
Description:
CVE (CAN) ID: CVE-2016-4167
Adobe dng sdk supports reading and writing DNG files, and can also be converted into DNG data formats that are easy to process and display.
Adobe DNG Software Development Kit (SDK) 1.4 and earlier versions have security vulnerabilities. Remote attackers can exploit this vulnerability to execute arbitrary code or cause DoS attacks.
<* Source: Kinan Hakim
Link: https://helpx.adobe.com/security/products/dng-sdk/apsb16-19.html
*>
Suggestion:
Vendor patch:
Adobe
-----
Adobe has released a Security Bulletin (apsb16-19) and patches for this:
Apsb16-19: Security update available for the Adobe DNG Software Development Kit (SDK)
Link: https://helpx.adobe.com/security/products/dng-sdk/apsb16-19.html
Patch download: https://www.adobe.com/support/downloads/dng/dng_sdk.html
This article permanently updates the link address: