
====================================================================

                             CERT-Renater

                 Note d'Information No. 2019/VULN089

_____________________________________________________________________

DATE                : 11/04/2019

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Adobe XD versions prior to 17.0.12.

=====================================================================
https://helpx.adobe.com/security/products/xd/apsb19-22.html
_____________________________________________________________________

Adobe Security Bulletin

Security Updates Available for Adobe XD | APSB19-22
+-------------------------+--------------------------------+------------------+
|Bulletin ID              |Date Published                  |Priority
      |
+-------------------------+--------------------------------+------------------+
|APSB19-22                |April 09, 2019                  |3
      |
+-------------------------+--------------------------------+------------------+


Summary

Adobe has released updates for Adobe XD for macOS. These updates resolve
critical vulnerabilities in Adobe XD v16.0 and earlier versions.
Successful exploitation could lead to arbitrary code execution in the
context of the current user.


Affected Versions

+----------------------+-------------------------+---------+
|       Product        |         Version         |Platform |
+----------------------+-------------------------+---------+
|Adobe XD              |16.0 and earlier versions|macOS    |
+----------------------+-------------------------+---------+


Solution

Adobe recommends updating via the Creative Cloud desktop app's update
mechanism.  For more information, please reference this help page.

+--------------------------+-----------------------+--------------------------+
|Product                   |Version                |Platform
      |
+--------------------------+-----------------------+--------------------------+
|Adobe XD                  |17.0.12                |macOS
      |
+--------------------------+-----------------------+--------------------------+

For managed environments, IT administrators can use the Admin Console to
deploy Creative Cloud applications to end users. Refer to this help page
for more information.


Vulnerability details

+----------------------+------------------------+---------+--------------+
|Vulnerability Category|Vulnerability Impact    |Severity |CVE Numbers   |
+----------------------+------------------------+---------+--------------+
|Path traversal        |Arbitrary code execution|Critical |CVE-2019-7105 |
+----------------------+------------------------+---------+--------------+
|Path traversal        |Arbitrary code execution|Critical |CVE-2019-7106 |
+----------------------+------------------------+---------+--------------+

Acknowledgments

Adobe would like to thank Zhongcheng Li(CK01) of Topsec Alpha Team for
reporting these issues and for working with Adobe to help protect our
customers.


=========================================================
+ CERT-RENATER        | tel : 01-53-94-20-44            +
+ 23/25 Rue Daviel    | fax : 01-53-94-20-41            +
+ 75013 Paris         | email:cert@support.renater.fr   +
=========================================================





