ZeroHour
Security Affairspublished ()ingested @securityaffairs

Adobe addresses 'Important' Flaws in Connect, Digital Editions

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-12817
Adobe Digital Editions versions 4.5.9 and below have an out of bounds read vulnerability.

Adobe Digital Editions versions 4.5.9 and below have an out of bounds read vulnerability. Successful exploitation could lead to information disclosure.

NVD description · AI analysis pending
7.53%
  • adobe digital editions
CVE-2018-19718
Adobe Connect versions 9.8.1 and earlier have a session token exposure vulnerability.

Adobe Connect versions 9.8.1 and earlier have a session token exposure vulnerability. Successful exploitation could lead to exposure of the privileges granted to a session.

NVD description · AI analysis pending
5.33%
  • adobe connect
Full article256 words · extracted from securityaffairs.com · click to collapse

Adobe’s Patch Tuesday security updates for January 2019 fix two flaws rated as “important” in the Connect and Digital Editions products.

Adobe’s Patch Tuesday security updates for January 2019 fix two “important” vulnerabilities in the Connect and Digital Editions ebook reader products.

The first flaw, tracked as CVE-2018-19718, is a session token exposure issue that affects the Adobe Connect web conferencing software. The vulnerability could lead to the exposure of privileges granted to a session, it affects Adobe Connect version 9.8.1 and earlier for all platforms.

The second flaw, tracked as CVE-2018-12817, is an out-of-bounds read bug that affects the Digital Editions ebook reader software. The flaw can result in the disclosure of information in the context of the current user, it affects Adobe Digital Editions version 4.5.9 and earlier on Windows, macOS, iOS and Android platforms. The vulnerability was reported by Jaanus Kääp of Clarified Security.

The good news is that Adobe is not aware of cyber attacks in the wild exploiting the two flaws, experts believe that the likelihood of their exploitation is very low. Both flaws were rated as important and received a priority rating of 3.

On January 3, Adobe released security updates that address two critical vulnerabilities in the Acrobat and Reader products, a use-after-free issue and a security bypass flaw.

The flaws affect the latest versions of Acrobat DC, Acrobat Reader DC, Acrobat 2017 and Acrobat Reader DC 2017 for Windows and macOS.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Adobe, Connect)

[adrotate banner=”5″] [adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/79663/security/connect-digital-editions-flaws.html