Adobe Photoshop CS6 for Mac Multiple RCE Vulnerabilities (APSB12-20) (Mac OS X)

critical Nessus Plugin ID 62222

Synopsis

The remote host has an application that is affected by multiple remote code execution vulnerabilities.

Description

The version of Adobe Photoshop installed on the remote Mac OS X host is prior to CS6 13.0.1. It is, therefore, affected by remote code execution vulnerabilities due to multiple buffer overflows. A remote attacker, using a crafted file, can exploit these to execute arbitrary code.

Solution

Upgrade to Adobe Photoshop CS6 13.0.1 or later.

See Also

http://secunia.com/secunia_research/2012-29/

http://www.adobe.com/support/security/bulletins/apsb12-20.html

Plugin Details

Severity: Critical

ID: 62222

File Name: macosx_adobe_photoshop_apsb12-20.nasl

Version: 1.8

Type: local

Agent: macosx

Published: 9/21/2012

Updated: 7/14/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:adobe:photoshop, cpe:/a:adobe:photoshop_cs6

Required KB Items: Host/local_checks_enabled, Host/MacOSX/Version, installed_sw/Adobe Photoshop

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/30/2012

Vulnerability Publication Date: 8/30/2012

Reference Information

CVE: CVE-2012-0275, CVE-2012-4170

BID: 55333, 55372