ZeroHour
Security Affairspublished ()ingested @securityaffairs

Out-of-band security update fixes Adobe Media Encoder issue

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-9739
+2 in the same advisory: …9744 …9745
Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated b

Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

NVD description · AI analysis pending
7.12%
  • adobe media encoder
Full article215 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 15, 2020

Adobe has released an out-of-band security update to address three ‘Important’ security vulnerabilities in the Adobe Media Encoder.

Adobe has released an out-of-band security update for Adobe Media Encoder that addresses three ‘Important’ Information Disclosure flaws.

The three vulnerabilities could be exploited by an attacker to access sensitive information that is leaked in the security of the active user.

Adobe recommends users to install the security updates to prevent the exploitation of the above issued in attacks aimed at unpatched installs.

“Adobe has released an update for Media Encoder.  This update resolves important out-of-bounds read vulnerabilities that could lead to information disclosure in the context of the current user.” reads the APSB20-57 Security bulletin.

Below the list of vulnerabilities fixed by adobe:

Vulnerability CategoryVulnerability ImpactSeverityCVE Numbers
Out-of-Bounds ReadInformation Disclosure      ImportantCVE-2020-9739  CVE-2020-9744  CVE-2020-9745  

These vulnerabilities have been reported by Radu Motspan. 

Users should install Media Encoder 14.4 to address the above issues.

Last week, Adobe has released security updates to address twelve critical vulnerabilities that could be exploited by attackers to execute arbitrary code on systems running vulnerable versions of Adobe InDesign, Adobe Framemaker, and Adobe Experience Manager.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, out of band patch)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/108329/security/adobe-media-encoder-flaws.html