First published: Fri Jun 26 2020(Updated: )
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Digital Negative Software Development Kit | <=1.5 | |
Apple iOS and macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-9628 is considered to be medium due to the potential for information disclosure.
To fix CVE-2020-9628, update to the latest version of the Adobe DNG Software Development Kit beyond 1.5.
Exploitation of CVE-2020-9628 may allow an attacker to gain access to sensitive information through out-of-bounds read vulnerabilities.
CVE-2020-9628 affects Adobe DNG Software Development Kit versions 1.5 and earlier.
Apple macOS and Microsoft Windows are not affected by CVE-2020-9628 as the vulnerability is specific to the Adobe DNG SDK.