9.3
CVSSv2

CVE-2012-2052

Published: 19/06/2014 Updated: 20/06/2014
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the U3D.8BI library plugin in Adobe Photoshop CS5 12.x prior to 12.0.5 and CS5.1 12.1.x prior to 12.1.1 allows remote malicious users to execute arbitrary code via a long Collada asset element in a DAE file, as demonstrated by the cameraYFov value in the contributor comments element.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe photoshop cs5.1 12.1

adobe photoshop cs5 12.0

adobe photoshop cs5 12.0.2

adobe photoshop cs5 12.0.4

adobe photoshop cs5 12.0.1

adobe photoshop cs5 12.0.3

Exploits

<?php // ~ Adobe Photoshop CS51 U3D8bi Library Collada Asset Elements // Unicode Conversion Stack Based Buffer Overflow poc (*dae) // (32bit/SEH) ~ // // unicode overflow occurs when overlong asset elements are processed // one could be able to return inside an ASCII memory region // with an ultra large nop through assigning eip to ex Photo ...