First published: Thu Oct 09 2014(Updated: )
Adobe Digital Editions (DE) 4 does not use encryption for transmission of data to adelogs.adobe.com, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by book-navigation information.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Digital Editions | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8068 is classified as a medium severity vulnerability due to its potential for information leakage.
CVE-2014-8068 affects Adobe Digital Editions 4 by transmitting sensitive data in plain text, which can be intercepted by attackers.
To mitigate CVE-2014-8068, users should upgrade to the latest version of Adobe Digital Editions that addresses this security issue.
CVE-2014-8068 allows attackers to access sensitive information such as book-navigation logs transmitted to Adobe servers.
Currently, the best workaround for CVE-2014-8068 is to avoid using Adobe Digital Editions 4 and consider alternative e-book management software.