ZeroHour
Security Affairspublished ()ingested @securityaffairs

Adobe addresses five issues in ColdFusion, After Effects, Digital Editions

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-3768
+2 in the same advisory: …3796 …3767
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a dll search-order hijacking vulnerability.

ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.

NVD description · AI analysis pending
7.8
group max
<1%
  • adobe coldfusion
CVE-2020-3798
Adobe Digital Editions versions 4.5.11.187212 and below have a file enumeration (host or local network) vulnerability.

Adobe Digital Editions versions 4.5.11.187212 and below have a file enumeration (host or local network) vulnerability. Successful exploitation could lead to information disclosure.

NVD description · AI analysis pending
6.55%
  • adobe digital editions
CVE-2020-3809
Adobe After Effects versions 17.0.1 and earlier have an out-of-bounds read vulnerability.

Adobe After Effects versions 17.0.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

NVD description · AI analysis pending
5.52%
  • adobe after effects
Full article273 words · extracted from securityaffairs.com · click to collapse

Adobe has addressed five minor vulnerabilities in its ColdFusion, After Effects and Digital Editions products.

Adobe has addressed five vulnerabilities in its ColdFusion, After Effects and Digital Editions products.

“Adobe has published security bulletins for Adobe ColdFusion (APSB20-18), Adobe After Effects (APSB20-21) and Digital Editions (APSB20-23). Adobe recommends users update their product installations to the latest versions using the instructions referenced in the bulletin.” reads the advisory published by Adobe.

Three important severity vulnerabilities affect ColdFusion versions 2016 and 2018, the issues could respectively lead to information disclosure (CVE-2020-3767), privilege escalation (CVE-2020-3768), or a denial-of-service (CVE-2020-3796).

The vulnerabilities have been reported by  Jason Troy (CVE-2020-3767), Nuttakorn Tungpoonsup and Ammarit Thongthua from Secure D Center Research Team, Secure D Center Co.,Ltd. And Sittikorn Sangrattanapitak – Cybersecurity Researcher (CVE-2020-3768), and Raki Ben Hamouda (CVE-2020-3796).

The company also addressed an important out-of-bounds read vulnerability in After Effects that could lead to information disclosure in the context of the current user.

The flaw tracked as CVE-2020-3809, was reported by Matt Powell of Trend Micro’s Zero Day Initiative for reporting.

Last issue fixed by the IT firm affects Digital Editions product, it is an important information disclosure flaw related to file enumeration.

The flaw, tracked as CVE-2020-3798, has been reported by Jason Troy, Raki Ben Hamouda, and researchers from imec-DistriNet at KU Leuven, Trend Micro’s Zero Day Initiative, and Secure D.

None of these vulnerabilities has been exploited in attacks in the wild, the company believes that it is unlikely that attackers could exploit it soon.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Patch Tuesday, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/101585/security/adobe-coldfusion-after-effects-digital-editions-flaws.html