CVE-2014-8068: Infoleak
Adobe Digital Editions (DE) 4 does not use encryption for transmission of data to adelogs.adobe.com, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by book-navigation information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8068?
CVE-2014-8068 is classified as a medium severity vulnerability due to its potential for information leakage.
How does CVE-2014-8068 affect Adobe Digital Editions?
CVE-2014-8068 affects Adobe Digital Editions 4 by transmitting sensitive data in plain text, which can be intercepted by attackers.
How do I fix CVE-2014-8068?
To mitigate CVE-2014-8068, users should upgrade to the latest version of Adobe Digital Editions that addresses this security issue.
What information can be compromised due to CVE-2014-8068?
CVE-2014-8068 allows attackers to access sensitive information such as book-navigation logs transmitted to Adobe servers.
Is there a workaround for CVE-2014-8068?
Currently, the best workaround for CVE-2014-8068 is to avoid using Adobe Digital Editions 4 and consider alternative e-book management software.