CVE-2024-34139: Adobe Bridge has an integer overflow vulnerability when parsing SVG file
Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34139?
CVE-2024-34139 has a high severity as it involves an Integer Overflow vulnerability that could lead to arbitrary code execution.
How do I fix CVE-2024-34139?
To mitigate CVE-2024-34139, upgrade Adobe Bridge to version 14.1.1 or later, or 13.0.8 if using an earlier version.
What versions of Adobe Bridge are affected by CVE-2024-34139?
CVE-2024-34139 affects Adobe Bridge versions 14.0.4, 13.0.7, 14.1, and earlier.
What type of vulnerability is CVE-2024-34139?
CVE-2024-34139 is classified as an Integer Overflow or Wraparound vulnerability.
Is user interaction required for the exploitation of CVE-2024-34139?
Yes, exploitation of CVE-2024-34139 requires user interaction, such as opening a malicious file.