CVE-2007-2365
published 2007-04-30CVE-2007-2365: Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute…
PriorityP352critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
51.05%
98.8th percentile
Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | golive | — | — |
| adobe | illustrator | — | — |
| adobe | photoshop | — | — |
| adobe | photoshop_elements | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
\x89\x50\x4e\x47\x0d\x0a\x1a\x0a\x00\x00\x00\x0d\x49\x48\x44\x52
- →Exploit payload uses PexFnstenvSub encoder (Metasploit); network or endpoint detection should look for this encoder's characteristic byte patterns (\x29\xc9\x83\xe9 or \x31\xc9\x83\xe9) embedded inside PNG files. ↗
- →Bind-shell payload listens on TCP port 4444 after successful exploitation; monitor for unexpected outbound/inbound connections on port 4444 from Photoshop or related processes. ↗
- →The exploit targets Windows XP SP2; prioritize detection on legacy Windows XP endpoints running the affected Adobe/Corel applications. ↗
- →The malicious PNG contains a valid PNG header (\x89PNG\r\n\x1a\n) followed by an IHDR chunk and then a large IDAT block embedding shellcode; inspect PNG files for shellcode patterns within compressed IDAT data. ↗
- ·The exploit was tested specifically against Windows XP SP2 French edition; exploit reliability on other OS versions or service packs is not confirmed by the source. ↗
- ·The vulnerability also affects Adobe Illustrator CS3 and GoLive 9 per the NVD advisory, but the proof-of-concept exploit code only targets Photoshop CS2/CS3, Photoshop Elements 5.0, and Corel Paint Shop Pro 11.20. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat4.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x3cm-hj4w-q575: Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5
ghsa_unreviewed·2022-05-01
CVE-2007-2365 [HIGH] CWE-119 GHSA-x3cm-hj4w-q575: Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5
Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.
Red Hat
kernel: ptrace: Crash on PTRACE_{ATTACH,DETACH} race
vendor_redhat·2008-04-02·CVSS 4.9
CVE-2008-2365 [MEDIUM] kernel: ptrace: Crash on PTRACE_{ATTACH,DETACH} race
kernel: ptrace: Crash on PTRACE_{ATTACH,DETACH} race
Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's process that trigger a conflict between utrace_detach and report_quiescent, related to "late ptrace_may_attach() check" and "race around &dead_engine_ops setting," a different vulnerability than CVE-2007-0771 and CVE-2008-1514. NOTE: this issue might only affect kernel versions before 2.6.16.x.
No detection rules found.
No writeups or analysis indexed.
http://osvdb.org/35465http://osvdb.org/38063http://secunia.com/advisories/25044http://secunia.com/advisories/26846http://secunia.com/advisories/26864http://securitytracker.com/id?1018792http://www.adobe.com/support/security/bulletins/apsb07-13.htmlhttp://www.adobe.com/support/security/bulletins/apsb07-16.htmlhttp://www.adobe.com/support/security/bulletins/apsb07-17.htmlhttp://www.securityfocus.com/bid/23698http://www.vupen.com/english/advisories/2007/1577http://www.vupen.com/english/advisories/2007/3442http://www.vupen.com/english/advisories/2007/3443https://exchange.xforce.ibmcloud.com/vulnerabilities/33956https://www.exploit-db.com/exploits/3812http://osvdb.org/35465http://osvdb.org/38063http://secunia.com/advisories/25044http://secunia.com/advisories/26846http://secunia.com/advisories/26864http://securitytracker.com/id?1018792http://www.adobe.com/support/security/bulletins/apsb07-13.htmlhttp://www.adobe.com/support/security/bulletins/apsb07-16.htmlhttp://www.adobe.com/support/security/bulletins/apsb07-17.htmlhttp://www.securityfocus.com/bid/23698http://www.vupen.com/english/advisories/2007/1577http://www.vupen.com/english/advisories/2007/3442http://www.vupen.com/english/advisories/2007/3443https://exchange.xforce.ibmcloud.com/vulnerabilities/33956https://www.exploit-db.com/exploits/3812
2007-04-30
Published