Adobe Content Authenticity SDK Integer Underflow Vulnerability Leading to Denial-of-Service
Vulnerability
A denial-of-service vulnerability has been identified in Adobe Content Credentials, specifically in versions of the Content Authenticity JS SDK through 0.7.0 and the Content Authenticity Rust SDK through 0.78.2. This vulnerability arises from an integer underflow issue, which could be exploited to crash the application, causing a denial-of-service condition. Notably, exploitation of this vulnerability does not require user interaction.
Impact
Exploitation of this vulnerability can cause the application to crash, leading to a denial-of-service condition.
Remediation
Users are advised to update to the latest versions of the Content Authenticity JS SDK and Rust SDK. The updated version for the JS SDK is 0.7.1, and for the Rust SDK, it is 0.80.1.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
