FYI…

- http://secunia.com/advisories/29838/
Release Date: 2008-04-22
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: -Unpatched-
Software: Adobe After Effects CS3, Adobe Photoshop Album Starter Edition 3.x…

- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1765
Last revised: 4/23/2008
Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically proximate attackers to execute arbitrary code via a BMP file with an invalid image header. NOTE: the related issue in Photoshop CS3 is already covered by CVE-2007-2244*.
CVSS v2 Base score: 9.3 (High)
Impact Type: Provides administrator access, Allows complete confidentiality, integrity, and availability violation, Allows unauthorized disclosure of information, Allows disruption of service…
* http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2244

- http://www.adobe.com/support/security/advi…/apsa08-04.html
"…Adobe is working to address the issue… Adobe categorizes this as a critical issue and recommends that Photoshop Album Starter Edition 3.2 customers exercise caution when receiving unsolicited or suspicious BMP files."

:ph34r: