CVE-2023-26346: ZDI-CAN-19495: Adobe Dimension USD File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-26346?
CVE-2023-26346 is an out-of-bounds read vulnerability affecting Adobe Dimension versions 3.4.7 and earlier.
How severe is CVE-2023-26346?
CVE-2023-26346 has a severity rating of 5.5, which is considered medium.
How does CVE-2023-26346 affect Adobe Dimension?
CVE-2023-26346 allows for disclosure of sensitive memory and the bypassing of mitigations such as ASLR in Adobe Dimension versions 3.4.7 and earlier.
How can CVE-2023-26346 be exploited?
Exploiting CVE-2023-26346 requires user interaction, such as a victim opening a malicious file or visiting a specially crafted website.
Is there a fix available for CVE-2023-26346 in Adobe Dimension?
Yes, upgrading to Adobe Dimension version 3.4.8 or later will fix CVE-2023-26346.