This application requires Javascript for optimal performance.

Adobe.Illustrator.Encapsulated.Postscript.File.Buffer.Overflow

Release Date

Jan 12, 2010

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit a remote code execution vulnerability in Adobe Illustrator.

The vulnerability is caused by an error when handling malformed .EPS file. It can be exploited via a crafted EPS file, leading to remote code execution.

Affected Products

Adobe Illustrator CS4
Adobe Illustrator CS3

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-4195

Reference/s

http://www.securityfocus.com/bid/37192 (BugTraq)

Reference: VID-18030