news4geeks.net
10May/120

Adobe: Photoshop is not a target for attackers


Adobe logo Adobe have responded to the suggestion that they are effectively charging for security updates, saying that they do not believe that "the real-world risk to customers warranted an out-of band release to resolve these issues". On Wednesday, a security bulletin issued by Adobe pointed out security flaws in Photoshop CS5/CS5.5 and Illustrator CS5/CS5.5, but offered only a paid-for upgrade to the very recently released CS6 versions of the applications as a fix for the flaws.

Contacted by The H's associates at heise Security, the company says it rated the APSB12-11 security bulletin a "priority 3 update" on the basis that "it is a product that has historically not been a target for attackers" and that it was not aware of any exploits targeting the issues that they had fixed. Adobe may be categorising exploits as "code used in anger to cause damage", because there is at least one proof of concept exploit for one of the APSB12-11 vulnerabilities.

Releasing a security advisory will, however, have raised awareness with attackers – especially attackers who use spear-phishing tactics aimed at particular categories of users within an organisation – that such holes exist in Photoshop and that they are potentially exploitable. Adobe says that installation of the upgrade "is therefore at the user's/administrator's discretion". The company also said that no "dot release" or update was scheduled for either Photoshop CS5 or CS5.5 where an "in-band" fix would have been included, so the flaws are likely to persist in the wild for a number of years.

(Source: h-online.com)

 

Adobe to launch new software suite for designers
Adobe is launching the latest version of its software package for designers and Web developers. Adobe Systems Inc. is set to announce CS6 on Monday at an event in San Francisco. ...
READ MORE
Got Photoshop CS5? There are three apps for that
Continuing its foray in iOS software Adobe today released three companion apps for Photoshop CS5. The apps provide a range of new ways to interact with Photoshop with ...
READ MORE
McAfee said it has found a vulnerability in Adobe Systems' Reader program that reveals when and where a PDF document is opened. The issue is not a serious problem and does ...
READ MORE
Microsoft's Windows 8 is vulnerable to attack by exploits that hackers have been aiming at PCs for several weeks, Adobe has confirmed. Microsoft said it will not patch the ...
READ MORE
Adobe yesterday updated Flash Player to solve a weeks-long problem for users of Mozilla's Firefox browser. The update, Flash Player 11.3.300.262, was released Thursday and applies only to Firefox on Windows. Since ...
READ MORE
Adobe to launch new software suite for designers
Got Photoshop CS5? There are three apps for
McAfee spots Adobe Reader PDF-tracking flaw
Adobe confirms Windows 8 users vulnerable to active
Adobe fixes Flash Player for Firefox to stop

Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

Trackbacks are disabled.