Reader: JavaScript util.printf() function buffer overflow
Published Nov 4, 2008 ·Due Mar 24, 2022
7.8
HIGHCVSS 3.1
EPSS 98.48%
Description
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.
Affected products
No data.
No data.
Extras for RHEL 3
acroread-0:8.1.3-1
Fixed · RHSA-2008:0974
Extras for RHEL 4
acroread-0:8.1.3-1.el4
Fixed · RHSA-2008:0974
Supplementary for Red Hat Enterprise Linux 5
acroread-0:8.1.3-1.el5
Fixed · RHSA-2008:0974
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 3 | acroread-0:8.1.3-1 | Fixed | RHSA-2008:0974 |
| Extras for RHEL 4 | acroread-0:8.1.3-1.el4 | Fixed | RHSA-2008:0974 |
| Supplementary for Red Hat Enterprise Linux 5 | acroread-0:8.1.3-1.el5 | Fixed | RHSA-2008:0974 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Date Added
Mar 3, 2022
Patch Due
Mar 24, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 10, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 98.48% (0.98482) | 99.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 98.46% (0.98463) | 99.91th | v5 (v2026.06.15) |
| Mar 17, 2025 | 93.95% (0.93947) | 99.88th | v4 (v2025.03.14) |
| Dec 17, 2024 | 93.84% (0.93842) | 99.35th | v3 (v2023.03.01) |
| Dec 12, 2024 | 97.16% (0.97160) | 99.85th | v3 (v2023.03.01) |
| Jul 17, 2024 | 97.27% (0.97272) | 99.87th | v3 (v2023.03.01) |
| May 15, 2024 | 97.18% (0.97176) | 99.81th | v3 (v2023.03.01) |
| Apr 9, 2024 | 97.22% (0.97225) | 99.82th | v3 (v2023.03.01) |
| Jan 29, 2024 | 97.17% (0.97167) | 99.77th | v3 (v2023.03.01) |
| Nov 18, 2023 | 97.22% (0.97225) | 99.79th | v3 (v2023.03.01) |
| Oct 12, 2023 | 97.24% (0.97242) | 99.78th | v3 (v2023.03.01) |
| Sep 4, 2023 | 97.37% (0.97373) | 99.86th | v3 (v2023.03.01) |
| Jun 15, 2023 | 97.36% (0.97361) | 99.83th | v3 (v2023.03.01) |
| May 5, 2023 | 97.11% (0.97115) | 99.62th | v3 (v2023.03.01) |
| Mar 24, 2023 | 97.41% (0.97405) | 99.84th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.44% (0.97438) | 99.88th | v3 (v2023.03.01) |
| Mar 6, 2023 | 86.35% (0.86350) | 99.71th | v2 (v2022.01.01) |
| Feb 4, 2022 | 86.35% (0.86350) | 99.65th | v2 (v2022.01.01) |
References (33)
- http://download.oracle.com/sunalerts/1019937.1.html vendor-advisoryx_refsource_SUNALERTThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://osvdb.org/49520 vdb-entryx_refsource_OSVDBBroken Link
- http://secunia.com/advisories/29773 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/32700 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/32872 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/35163 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/secunia_research/2008-14/ x_refsource_MISCBroken LinkVendor Advisory
- http://securityreason.com/securityalert/4549 third-party-advisoryx_refsource_SREASONBroken LinkExploit
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=800801 x_refsource_CONFIRMBroken Link
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=909609 x_refsource_CONFIRMBroken Link
- http://www.adobe.com/support/security/bulletins/apsb08-19.html x_refsource_CONFIRMBroken LinkPatchVendor Advisory
- http://www.coresecurity.com/content/adobe-reader-buffer-overflow x_refsource_MISCThird Party Advisory
- http://www.kb.cert.org/vuls/id/593409 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.redhat.com/support/errata/RHSA-2008-0974.html vendor-advisoryx_refsource_REDHATBroken LinkPatch
- http://www.securityfocus.com/archive/1/498027/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/498032/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/498055/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/30035 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/32091 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1021140 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/cas/techalerts/TA08-309A.html third-party-advisoryx_refsource_CERTBroken LinkThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2008/3001 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2009/0098 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-08-072/ x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2008-2992 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=469877 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2008-2992
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-2992 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2008-2992
- https://www.exploit-db.com/exploits/6994 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/7006 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://download.oracle.com/sunalerts/1019937.1.html | vendor-advisoryx_refsource_SUNALERTThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://osvdb.org/49520 | vdb-entryx_refsource_OSVDBBroken Link | |
| http://secunia.com/advisories/29773 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/32700 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/32872 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/advisories/35163 | third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory | |
| http://secunia.com/secunia_research/2008-14/ | x_refsource_MISCBroken LinkVendor Advisory | |
| http://securityreason.com/securityalert/4549 | third-party-advisoryx_refsource_SREASONBroken LinkExploit | |
| http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=800801 | x_refsource_CONFIRMBroken Link | |
| http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=909609 | x_refsource_CONFIRMBroken Link | |
| http://www.adobe.com/support/security/bulletins/apsb08-19.html | x_refsource_CONFIRMBroken LinkPatchVendor Advisory | |
| http://www.coresecurity.com/content/adobe-reader-buffer-overflow | x_refsource_MISCThird Party Advisory | |
| http://www.kb.cert.org/vuls/id/593409 | third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource | |
| http://www.redhat.com/support/errata/RHSA-2008-0974.html | vendor-advisoryx_refsource_REDHATBroken LinkPatch | |
| http://www.securityfocus.com/archive/1/498027/100/0/threaded | mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/archive/1/498032/100/0/threaded | mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/archive/1/498055/100/0/threaded | mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/30035 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/32091 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id?1021140 | vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.us-cert.gov/cas/techalerts/TA08-309A.html | third-party-advisoryx_refsource_CERTBroken LinkThird Party AdvisoryUS Government Resource | |
| http://www.vupen.com/english/advisories/2008/3001 | vdb-entryx_refsource_VUPENBroken LinkVendor Advisory | |
| http://www.vupen.com/english/advisories/2009/0098 | vdb-entryx_refsource_VUPENBroken LinkVendor Advisory | |
| http://www.zerodayinitiative.com/advisories/ZDI-08-072/ | x_refsource_MISCThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2008-2992 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=469877 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2008-2992 | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-2992 | government-resourceUS Government Resource | |
| https://www.cve.org/CVERecord?id=CVE-2008-2992 | ||
| https://www.exploit-db.com/exploits/6994 | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry | |
| https://www.exploit-db.com/exploits/7006 | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.