
====================================================================

                             CERT-Renater

                 Note d'Information No. 2021/VULN215
_____________________________________________________________________

DATE                : 14/04/2021

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Adobe Digital Editions versions
                                prior to 4.5.11.187606.

=====================================================================
https://helpx.adobe.com/security/products/Digital-Editions/apsb21-26.html
_____________________________________________________________________

Security Updates Available for Adobe Digital Editions | APSB21-26
Bulletin ID 	Date Published   Priority
APSB20-26 	April 13, 2021   3


Summary

Adobe has released a security update for Adobe Digital
Editions. This update resolves a critical vulnerability that could
result in arbitrary file system write.   


Affected product versions

Product                    Version                    Platform
Adobe Digital Editions     4.5.11.187245 and below     MacOS


Solution

Adobe categorizes these updates with the following priority ratings and
recommends users update their installation to the newest version:

Product 	Version 	Platform 	Priority 	Availability   Adobe Digital
Editions 	4.5.11.187606
	MacOS 	3 	Download Page

Note:

    Customers can download the update from the Adobe Digital Editions
download page, or utilize the product’s update mechanism when prompted.


    For more information, please refer the release notes.


Vulnerability details

Vulnerability Category 	Vulnerability Impact 	Severity    CVE Numbers
Privilege Escalation  	Arbitrary file system write   Critical
	CVE-2021-21100


Acknowledgments

Adobe would like to thank  Qingyang Chen for reporting these issues and
for working with Adobe to help protect our customers. 


=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================


