CVE-2017-11273: Infoleak
Published Dec 9, 2017
·Updated
An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. Adobe Digital Editions parses crafted XML files in an unsafe manner, which could lead to sensitive information disclosure.
Affected Software
1 affected component
Adobe Digital Editions<=4.5.6
Event History
Dec 9, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2017-11273?
CVE-2017-11273 is a vulnerability in Adobe Digital Editions 4.5.6 and earlier versions that could lead to sensitive information disclosure.
2
How does Adobe Digital Editions handle XML files?
Adobe Digital Editions parses crafted XML files in an unsafe manner.
3
What is the severity of CVE-2017-11273?
The severity of CVE-2017-11273 is medium with a CVSS score of 5.5.
4
How can CVE-2017-11273 be exploited?
CVE-2017-11273 can be exploited by providing a specially crafted XML file.
5
How do I protect myself from CVE-2017-11273?
To protect yourself from CVE-2017-11273, update Adobe Digital Editions to version 4.5.7 or later.