Bulletin ID
Security Updates Available for Brackets | APSB19-57
| 
                    
     | 
                
            
                
                    
     Date Published  | 
                
            
                
                    
     Priority  | 
                
            
        
|---|---|---|
| 
                    
     APSB19-57  | 
            
                
                
                    
     December 10, 2019  | 
            
                
                
                    
     3  | 
            
        
Summary
Adobe has released a security update for Brackets for Windows, macOS and Linux. This update addresses a critical vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Affected Versions
| 
                    
     Product  | 
                
            
                
                    
     Version  | 
                
            
                
                    
     Platform  | 
                
            
        
|---|---|---|
| 
                    
     Brackets  | 
            
                
                
                    
     1.14 and earlier versions  | 
            
                
                
                    
     Windows, Linux & macOS  | 
            
        
Solution
Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:
| 
                    
     Product  | 
                
            
                
                    
     Version  | 
                
            
                
                    
     Platform  | 
                
            
                
                    
     Priority Rating  | 
                
            
                
                    
     Availability  | 
                
            
        
|---|---|---|---|---|
| 
                    
     Brackets  | 
            
                
                
                    
     1.14.1  | 
            
                
                
                    
     Windows, Linux & macOS  | 
            
                
                
                    
     3  | 
            
                
                
Vulnerability details
| 
                    
     Vulnerability Category  | 
                
            
                
                    
     Vulnerability Impact  | 
                
            
                
                    
     Severity  | 
                
            
                
                    
     CVE Numbers  | 
                
            
        
|---|---|---|---|
| 
                    
     Command Injection  | 
            
                
                
                    
     Arbitrary code execution  | 
            
                
                
                    
     Critical  | 
            
                
                
                    
     CVE-2019-8255  | 
            
        
Acknowledgments
Adobe would like to thank Tavis Ormandy of Google project zero for reporting this issue and for working with Adobe to help protect our users.