积极预防 及时发现
快速响应 力保恢复
Adobe PhotoDeluxe是一款图象编辑制作软件,它运行于Microsoft Windows...
发布时间:2002-03-12 信息来源:管理员

CNCVE编号:CNCVE-20020051 CVE编号: 安全级别:中 漏洞中文描述: Adobe PhotoDeluxe是一款图象编辑制作软件,它运行于Microsoft Windows 9x/ME/NT/2001/XP操作系统。Adobe PhotoDeluxe在公用目录安装了敏感的Java代码。Adobe PhotoDeluxe的一个特性是允许用户从Adobe的站点下载额外的设计组件,这个被称为"Connectables"的功能是通过安装在用户系统的Java代码实现的。然而Java applet安装方式不安全,这可以通过恶意的网页或HTML类型的 e-mail查看。这将造成非授权访问用户系统的敏感信息泄漏,甚至执行任意代码。 漏洞英文描述: Adobe PhotoDeluxe is image editing/photo album software that ships with a number of imaging devices. It runs on Microsoft Windows 9x/ME/NT/2000/XP operating systems. Adobe PhotoDeluxe installs sensitive Java code in a public location. One of Adobe PhotoDeluxe's features is to allow users to download extra design elements from the Adobe website. The functionality is called "Connectables" and is accomplished via the installation of Java code on the user's system. However, the Java applet is installed in an insecure manner, which may be exploited by malicious webpages or HTML e-mail viewed through the Internet Explorer web browser. This may grant unauthorized access to sensitive information on an affected user's system. This problem, in some cases, may also result in the execution of arbitrary code. Versions of Adobe PhotoDeluxe also exist for MacOS, though it is not known whether they are affected by this issue. 漏洞参考: http://www.kb.cert.org/vuls/id/116875 http://www.adobe.com 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误