==================================================================== CERT-Renater Note d'Information No. 2019/VULN088 _____________________________________________________________________ DATE : 11/04/2019 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Adobe Dreamweaver versions prior to 19.1. ===================================================================== https://helpx.adobe.com/security/products/dreamweaver/apsb19-21.html _____________________________________________________________________ Adobe Security Bulletin Security update available for Adobe Dreamweaver | APSB19-21 +-------------------------+--------------------------------+------------------+ |Bulletin ID |Date Published |Priority | +-------------------------+--------------------------------+------------------+ |APSB19-21 |April 09, 2019 |3 | +-------------------------+--------------------------------+------------------+ Summary Adobe has released a security update for Adobe Dreamweaver. This update resolves a vulnerability rated moderate related to the use of the Server Message Block (SMB) protocol when handling UNC paths in Dreamweaver. Affected Versions +----------------------+----------------------+----------------------+ | Product | Affected Versions | Platform | +----------------------+----------------------+----------------------+ |Adobe Dreamweaver |19.0 and earlier |Windows and macOS | | |versions | | +----------------------+----------------------+----------------------+ Solution Adobe categorizes this update with the following priority rating and recommends users update their software installations via the Creative Cloud desktop app updater, or by navigating to the Dreamweaver Help menu and clicking "Updates." For more information, please reference this help page. +--------------------+-----------------+--------------------+-----------------+ | Product | Updated Version | Platform | Priority rating | +--------------------+-----------------+--------------------+-----------------+ |Adobe Dreamweaver |19.1 |Windows and macOS |3 | +--------------------+-----------------+--------------------+-----------------+ Note: For managed environments, IT administrators can use the Creative Cloud Packager to create deployment packages. Refer to this help page for more information on the Creative Cloud Packager. Vulnerability Details +--------------+------------------------------+--------+----------------------+ |Vulnerability | Vulnerability Impact |Severity| CVE Numbers | | Category | | | | +--------------+------------------------------+--------+----------------------+ |Insecure |Sensitive data disclosure if | | | |protocol |SMB request is subject to a |Moderate|CVE-2019-7097 | |implementation|relay attack | | | +--------------+------------------------------+--------+----------------------+ ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================