Out-of-Bounds Read Vulnerability in Adobe DNG Software Development Kit
CVE-2020-9624

5.5MEDIUM

Key Information:

Vendor
Adobe
Vendor
CVE Published:
26 June 2020

Summary

The Adobe DNG Software Development Kit (SDK) versions 1.5 and earlier are vulnerable to an out-of-bounds read, which can potentially allow attackers to access sensitive information. This vulnerability can be exploited if the attacker is able to manipulate the software in a way that leads the application to process unexpected memory, resulting in unintended information disclosure. Developers using affected versions should review Adobe's security advisories and apply necessary patches to safeguard against exploitation.

Affected Version(s)

Adobe DNG Software Development Kit (SDK) Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.