Graphics Tools - Publish.com
Publish.com Ziff-Davis Enterprise  
SEARCH · ONLINE MEDIA · MOBILE · WEB DESIGN · GRAPHICS TOOLS · PRINTING · PHOTO · TIPS · OPINIONS
Home arrow Graphics Tools arrow Adobe Patches Photoshop, Illustrator Flaws
Adobe Patches Photoshop, Illustrator Flaws
By Ryan Naraine

Rate This Article:
Add This Article To:
The Web design and print publishing software maker pushes out an "important" security update to cover code execution flaws in the Adobe Creative Suite 2 product.

Web and print publishing software maker Adobe Systems has pushed out security patches to cover a potentially serious code execution flaw in the Adobe Creative Suite 2 platform.

The flaw, which carries an "important" rating, affects Adobe Creative Suite 2, Adobe Photoshop CS2 and Adobe Illustrator CS2 on both Windows and Mac OS platforms.

San Jose, Calif.-based Adobe is working on a plan release security updates on a monthly cycle, but a spokesman told eWEEK that this batch of patches is not part of the scheduled updates that will be implemented later this year.

According to a security bulletin from Adobe, the vulnerability could be exploited by malicious hackers launch security bypass, data manipulation and privilege escalation attacks.

"If exploited, this vulnerability could allow a hostile user to replace program files with malicious or harmful code that could read, write, or destroy sensitive data if subsequently run by a privileged user," Adobe warned.

To read more about Adobe releasing a fix for a flaw in Reader and Acrobat, click here.

The flaw is caused due to insecure default file permissions being set on the installed files and folders.

This allows any non-privileged users on the system to remove the files or replace them with malicious binaries.

Adobe said the vulnerability presents a risk for shared, multi-user systems.

On such systems, the company said a hostile user could replace program files with dangerous code that would execute when subsequently run by a privileged user.

For advice on how to secure your network and applications, as well as the latest security news, visit Ziff Davis Internet's Security IT Hub.

The company warned that the malicious code could be used to read, write or completely destroy sensitive corporate data.

Adobe credited security researchers Sudhakar Govindavajhala and Andrew Appel of Princeton University for reporting the flaw.

The Adobe Creative Suite 2 is a print and Web publishing software that integrates imaging, illustration, stock photography and PDF file creation capabilities in one environment.

Click here to read more about Adobe plugging code execution holes in Reader and Acrobat.

It includes Adobe Photoshop CS2 for image editing, Adobe Illustrator CS2 for drawing and illustration, Adobe InDesign CS2 for page layout, Adobe GoLive CS2 for Web design and Adobe Acrobat for client review and print output.

The software suite also features the Version Cue CS2 for file sharing and versioning, Adobe Bridge for file browsing and organizing and Adobe Stock Photos for royalty-free images.




Discuss Adobe Patches Photoshop, Illustrator Flaws
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Graphics Tools Articles          >>> More By Ryan Naraine
 


Buyer's Guide
Explore hundreds of products in our Publish.com Buyer's Guide.
Web design
Content management
Graphics Software
Streaming Media
Video
Digital photography
Stock photography
Web development
View all >

ADVERTISEMENT


FREE ZIFF DAVIS ENTERPRISE ESEMINARS AT ESEMINARSLIVE.COM
  • Dec 10, 4 p.m. ET
    Eliminate the Drawbacks of Traditional Backup/Replication for Linux
    with Michael Krieger. Sponsored by InMage
  • Dec 11, 1 p.m. ET
    Data Modeling and Metadata Management with PowerDesigner
    with Joel Shore. Sponsored by Sybase
  • Dec 12, 12 p.m. ET
    Closing the IT Business Gap: Monitoring the End-User Experience
    with Michael Krieger. Sponsored by Compuware
  • Dec 12, 2 p.m. ET
    Enabling IT Consolidation
    with Michael Krieger. Sponsored by Riverbed & VMWare
  • VTS
    Join us on Dec. 19 for Discovering Value in Stored Data & Reducing Business Risk. Join this interactive day-long event to learn how your enterprise can cost-effectively manage stored data while keeping it secure, compliant and accessible. Disorganized storage can prevent your enterprise from extracting the maximum value from information assets. Learn how to organize enterprise data so vital information assets can help your business thrive. Explore policies, strategies and tactics from creation through deletion. Attend live or on-demand with complimentary registration!
    FEATURED CONTENT
    IT LINK DISCUSSION - MIGRATION
    A Windows Vista® migration introduces new and unique challenges to any IT organization. It's important to understand early on whether your systems, hardware, applications and end users are ready for the transition.
    Join the discussion today!



    .NAME Charging For Whois
    Whois has always been a free service, but the .NAME registry is trying to change that.
    Read More >>

    Sponsored by Ziff Davis Enterprise Group

    NEW FROM ZIFF DAVIS ENTERPRISE


    Delivering the latest technology news & reviews straight to your handheld device

    Now you can get the latest technology news & reviews from the trusted editors of eWEEK.com on your handheld device
    mobile.eWEEK.com

     


    RSS 2.0 Feed


    internet
    rss graphic Publish.com
    rss graphic Google Watch

    Video Interviews


    streaming video
    Designing Apps for Usability
    DevSource interviews usability pundit Dr. Jakob Nielsen on everything from the proper attitude for programmers to the importance of prototyping in design to the reasons why PDF, Flash and local search engines can hurt more than they help.
    ADVERTISEMENT