CVE-2012-2052
high · 9.3Stack-based buffer overflow in the U3D.8BI library plugin in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via a long Collada asset element in a DAE file, as demonstrated by the cameraYFov value in the contributor comments element.
9.3
CVSS
23.3%
EPSS (exploit prob.)
98th
EPSS percentile
2014-06-19
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | photoshop_cs5 | 12.0 |
| adobe | photoshop_cs5 | 12.0.1 |
| adobe | photoshop_cs5 | 12.0.2 |
| adobe | photoshop_cs5 | 12.0.3 |
| adobe | photoshop_cs5 | 12.0.4 |
| adobe | photoshop_cs5.1 | 12.1 |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/show/osvdb/81832
- http://retrogod.altervista.org/9sg_photoshock_adv.htm
- http://retrogod.altervista.org/9sg_photoshock_u3d.htm
- http://seclists.org/bugtraq/2012/May/58
- http://secunia.com/advisories/49160
- http://www.adobe.com/support/security/bulletins/apsb12-11.html
- http://www.securityfocus.com/bid/53464
- http://osvdb.org/show/osvdb/81832
- http://retrogod.altervista.org/9sg_photoshock_adv.htm
- http://retrogod.altervista.org/9sg_photoshock_u3d.htm
- http://seclists.org/bugtraq/2012/May/58
- http://secunia.com/advisories/49160
- http://www.adobe.com/support/security/bulletins/apsb12-11.html
- http://www.securityfocus.com/bid/53464
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-2052