• On TechRepublic: Why VISTA HATERS will love Windows 7

April 30, 2007 8:43 AM PDT

Critical flaw found in Photoshop plug-in

  • 10 comments
Security researchers have found a "highly critical" flaw in the portable-network graphics plug-in for the latest version of Adobe Systems' Photoshop Creative Suite, as well as for other versions of the software that run on Windows.

The portable-network graphics, or PNG, plug-in vulnerabilities were discovered in Adobe Photoshop Creative Suite 3 (CS3), Photoshop CS2, and Adobe Photoshop Elements (Editor) version 5.0 for Windows, according to a report released Monday by Secunia, which cited a researcher named "Marsu" with the discovery. Marsu tested a public exploit against versions of the software running Windows XP SP2.

These security flaws follow a report last week by Marsu that identified another set of critical vulnerabilities in Adobe Photoshop CS3 and CS2 for Windows.

The vulnerabilities reported on Monday can be exploited via a boundry error in the PNG.8BI Photoshop format plug-in when processing PNG files. Using a malicious PNG file, attackers can exploit the flaws to launch a buffer overflow attack to compromise the user's system.

See more CNET content tagged:
Adobe PhotoShop, Adobe Systems Inc., flaw, PNG, researcher

Add a Comment (Log in or register) (10 Comments)
  • prev
  • 1
  • next
Adobe - open to attack? Good!
by bobbydi April 30, 2007 2:47 PM PDT
Adobe products have been attacking other applications and basically trying to take over
personal computers. Adobe fixing the hole in that one program should be viewed as the big bully not getting what he deserved. Send the Grinch to work at Adobe for a while.
Reply to this comment
and Microsoft products...
by i_made_this April 30, 2007 4:13 PM PDT
...and Symantec's Norton product line and etc haven't done the same? and our ISP's haven't overchanged us as well as spied on our anti-spyware and other communications products? and Google doesn't warehouse the world's largest inventory of intimately personal information on each and every one on earth that uses the internet? and Sony didn't conscientiously nail our computers with the nastiest rootkit of all time? and Steve Jobs didn't know about the options deal??

please...the Grinch already works in the software industry and is the highest paid exec in the industry.

i don't mean to be sarcastic but really they all are criminals of greed and so forth. this stuff called software is a relatively brand new industry and the rules are still in their infancy. Supply and demand will rule eventually. And quality defines what governments, business enterprises and home users will pay.

Look at Win ME and now VISTA - dead in the water lol :p
View reply
GIMP
by ben::zen April 30, 2007 5:11 PM PDT
Yes, it doesn't have CMYK support, but the GIMP can do a lot. I use it for all my graphics work, and it handles all sorts of formats. Of course, then the "only open known files" line comes into play.
Reply to this comment
Oh NOES!!!!!
by Wazzpants May 1, 2007 4:16 PM PDT
WAAAAAAAA there's a flaw in the programming! we're all going to get hacked!
Oh wait, you have to open a bunk png file to do so, probably specifically created to exploit this vulnerability. Not a huge deal if you ask me.
Reply to this comment
(10 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Adobe Systems (-1.74%) -0.48 27.16
Dow Jones Industrials (0.53%) 44.13 8,324.87
S&P 500 (0.26%) 2.30 898.72
NASDAQ (-0.51%) -9.12 1,787.40
CNET TECH (67.49%) 519.65 1,289.66
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right