Release date: September 13, 2016
Last Updated: September 26, 2016
Vulnerability identifier: APSB16-28
Priority: 3
CVE numbers: CVE-2016-4256, CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, CVE-2016-4261, CVE-2016-4262, CVE-2016-4263, CVE-2016-6980
Platform: Windows, Macintosh, iOS and Android
Adobe has released a security update for Adobe Digital Editions for Windows, Macintosh, iOS and Android. This update resolves critical memory corruption vulnerabilities that could lead to code execution.
Product | Affected version | Platform |
---|---|---|
Adobe Digital Editions | 4.5.1 and earlier versions | Windows, Macintosh, iOS and Android |
Adobe categorizes this update with the following priority ratings and recommends users update their installation to the newest version:
Product | Updated version | Platform | Priority rating | Availability |
---|---|---|---|---|
Windows |
3 | Download Page | ||
Adobe Digital Editions | 4.5.2 | Macintosh | 3 | Download Page |
iOS | 3 | iTunes | ||
Android | 3 | Playstore |
Customers using Adobe Digital Editions 4.5.1 on Windows can download the update from the Adobe Digital Editions download page, or utilize the product’s update mechanism when prompted. Customers using Digital Editions for iOS and Android can download the update from the respective app store.
For more information, please reference the release notes.
- This update resolves multiple memory corruption vulnerabilities that could lead to code execution (CVE-2016-4256, CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, CVE-2016-4261, CVE-2016-4262).
- This update resolves a use-after-free vulnerability that could lead to code execution (CVE-2016-4263, CVE-2016-6980).
Adobe would like to thank the following individuals and organizations for reporting the relevant issues and for working with Adobe to help protect our customers:
- Ke Liu of Tencent's Xuanwu LAB (CVE-2016-4256, CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, CVE-2016-4261, CVE-2016-4262).
- Mario Gomes (@NetFuzzer) working with Trend Micro's Zero Day Initiative (CVE-2016-4263).
- Steven Seeley of Source Incite working with Trend Micro's Zero Day Initiative (CVE-2016-6980).