Bulletin ID
Security update available for the Adobe DNG Converter | APSB17-37
| 
                    
     | 
                
            
                
                    
     Date Published  | 
                
            
                
                    
     Priority  | 
                
            
        
|---|---|---|
| 
                    
     APSB17-37  | 
            
                
                
                    
     November 14, 2017  | 
            
                
                
                    
     3  | 
            
        
Summary
Adobe has released a security update for the Adobe DNG Converter for Windows. This update resolves a critical memory corruption vulnerability. 
Affected software versions
| 
                    
     Product  | 
            
                
                
                    
     Affected version  | 
            
                
                
                    
     Platform  | 
            
        
| 
                    
     Adobe DNG Converter  | 
            
                
                
                    
     9.12.1 and earlier versions  | 
            
                
                
                    
     Windows  | 
            
        
Solution
Adobe categorizes this update with the following priority rating and recommends users update their installation to the newest version:
| 
                    
     Product  | 
            
                
                
                    
     Updated version  | 
            
                
                
                    
     Platform  | 
            
                
                
                    
     Priority rating  | 
            
                
                
                    
     Availability  | 
            
        
| 
                    
     Adobe DNG Converter  | 
            
                
                
                    
     10.0  | 
            
                
                
                    
     Windows  | 
            
                
                
                    
     3  | 
            
                
                
Vulnerability Details
| 
                    
     Vulnerability Category  | 
                
            
                
                    
     Severity  | 
                
            
                
                    
     CVE Numbers  | 
                
            
        
|---|---|---|
| 
                    
     Memory Corruption  | 
            
                
                
                    
     Critical  | 
            
                
                
                    
     CVE-2017-11295  | 
            
        
Acknowledgments
Adobe would like to thank Kushal Arvind Shah of Fortinet's FortiGuard Labs for reporting this issue (CVE-2017-11295) and for working with Adobe to help protect our customers.