CVE-2024-34136: Adobe Illustrator PSD File Parsing Null Pointer dereference
Illustrator versions 28.5, 27.9.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS). An attacker could exploit this vulnerability to crash the application, resulting in a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34136?
CVE-2024-34136 is classified as a denial-of-service (DoS) vulnerability, which can crash Adobe Illustrator.
How do I fix CVE-2024-34136?
To mitigate CVE-2024-34136, update Adobe Illustrator to version 28.6 or later, or version 27.9.5 or later.
What versions of Illustrator are affected by CVE-2024-34136?
CVE-2024-34136 affects Adobe Illustrator versions 28.5, 27.9.4, and earlier.
Can exploiting CVE-2024-34136 allow remote attacks?
Exploiting CVE-2024-34136 does not typically allow for remote attacks but can crash the application if triggered.
Is there a specific operating system related to CVE-2024-34136?
CVE-2024-34136 specifically impacts Adobe Illustrator and is not tied to a particular operating system like macOS or Windows.