CVE-2020-9589
published 2020-06-26CVE-2020-9589: Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
7.60%
93.9th percentile
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_dng_software_development_kit | — | — |
| adobe | digital_negative_software_development_kit | <= 1.5 | — |
| android | — | — | |
| platform | external_dng_sdk | >= 10:0 < 10:2020-07-01 | 10:2020-07-01 |
| platform | external_dng_sdk | >= 8.0:0 < 8.0:2020-07-01 | 8.0:2020-07-01 |
| platform | external_dng_sdk | >= 8.1:0 < 8.1:2020-07-01 | 8.1:2020-07-01 |
| platform | external_dng_sdk | >= 9:0 < 9:2020-07-01 | 9:2020-07-01 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hr6m-jm36-qh4x: Adobe DNG Software Development Kit (SDK) 1
ghsa_unreviewed·2022-05-24
CVE-2020-9589 [HIGH] GHSA-hr6m-jm36-qh4x: Adobe DNG Software Development Kit (SDK) 1
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
OSV
CVE-2020-9589: In DecodeImage of dng_lossless_jpeg
osv·2020-07-01
CVE-2020-9589 CVE-2020-9589: In DecodeImage of dng_lossless_jpeg
In DecodeImage of dng_lossless_jpeg.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2020-9589: Android Security Bulletin 2020-07-01
CVE: CVE-2020-9589
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 8
vendor_android·2020-07-01·CVSS 7.8
CVE-2020-9589 [HIGH] CVE-2020-9589: Android Security Bulletin 2020-07-01
CVE: CVE-2020-9589
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 8
Android Security Bulletin 2020-07-01
CVE: CVE-2020-9589
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 8.0, 8.1, 9, 10
References: A-156261521
No detection rules found.
No public exploits indexed.
Talos
Threat Source newsletter for May 14, 2020
blogs_talos·2020-05-14
Threat Source newsletter for May 14, 2020
Newsletter compiled by Jon Munshaw.
Welcome to this week’s Threat Source newsletter — the perfect place to get caught up on all things Talos from the past week.
Our main focus this week is on Astaroth. This is a malware family that has been targeting Brazil with a variety of lures, including COVID-19-themed documents, for the past nine to 12 months. Astaroth implements a robust series of anti-analysis/evasion techniques, among the most thorough we've seen recently. We have the full rundown of the threat and our protections against it.
And, as always, we have the latest Threat Roundup where we go through the top threats we saw — and blocked — over the past week.
### Upcoming public engagements
Event: “Dynamic Data Resolver IDA plugin” at NSEC Online
Location: Streaming on Twitch
Date:
Talos
Threat Source newsletter for May 14, 2020
blogs_talos·2020-05-14
Threat Source newsletter for May 14, 2020
## Threat Source newsletter for May 14, 2020
Newsletter compiled by Jon Munshaw.
Welcome to this week’s Threat Source newsletter — the perfect place to get caught up on all things Talos from the past week.
Our main focus this week is on Astaroth. This is a malware family that has been targeting Brazil with a variety of lures, including COVID-19-themed documents, for the past nine to 12 months. Astaroth implements a robust series of anti-analysis/evasion techniques, among the most thorough we've seen recently. We have the full rundown of the threat and our protections against it .
And, as always, we have the latest Threat Roundup where we go through the top threats we saw — and blocked — over the past week.
## Upcoming public engagements
Event: “Dynamic Data Resolver IDA plugin” at NS
2020-06-26
Published