In association with heise online

8 January 2010, 15:20

Adobe patches holes in Illustrator

Adobe Illustrator Logo Adobe has released an update to close two critical security holes in Illustrator CS3 and CS4. Both the Windows and the Mac OS X versions are affected. One of the holes was already discovered in early December and is based on a buffer overflow that can be triggered when processing specially crafted "Encapsulated Postscript" (eps) files. An existing exploit for this vulnerability binds a shell to network port 4444 on vulnerable computers, allowing attackers to remotely access a Windows computer. The second hole is also based on a buffer overflow.

Under Windows, the update consists of one file (MPS.dll) which needs to be manually copied to the Illustrator installation folder. Adobe provides the required instructions in its original advisory. Under Mac OS X, a whole folder needs to be copy into the installation path. The relevant procedure can also be found in Adobe's advisory.

See also:

(crve)

  • Share this article
  • Twitter
  • Facebook
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit







The H open source

The H Security

The H Internet Toolkit