MEDIUM
acroread: multiple vulnerabilities in Adobe Reader 8.1.4
Published Apr 30, 2009
6.8
MEDIUMCVSS 2.0
EPSS 21.83%
Description
The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.
Affected products
No data.
No data.
Extras for RHEL 3
acroread-0:8.1.5-2
Fixed · RHSA-2009:0478
Extras for RHEL 4
acroread-0:8.1.5-1.el4
Fixed · RHSA-2009:0478
Supplementary for Red Hat Enterprise Linux 5
acroread-0:8.1.5-1.el5
Fixed · RHSA-2009:0478
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 3 | acroread-0:8.1.5-2 | Fixed | RHSA-2009:0478 |
| Extras for RHEL 4 | acroread-0:8.1.5-1.el4 | Fixed | RHSA-2009:0478 |
| Supplementary for Red Hat Enterprise Linux 5 | acroread-0:8.1.5-1.el5 | Fixed | RHSA-2009:0478 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (30)
- http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html x_refsource_MISCVendor Advisory
- http://blogs.adobe.com/psirt/2009/05/adobe_reader_issue_update.html x_refsource_CONFIRMThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00001.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://osvdb.org/54129 vdb-entryx_refsource_OSVDBBroken Link
- http://packetstorm.linuxsecurity.com/0904-exploits/spell.txt x_refsource_MISCExploit
- http://secunia.com/advisories/34924 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/35055 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/35096 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/35152 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/35358 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/35416 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/35734 third-party-advisoryx_refsource_SECUNIABroken Link
- http://security.gentoo.org/glsa/glsa-200907-06.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-259028-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=926953 x_refsource_CONFIRMThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb09-06.html x_refsource_CONFIRMThird Party Advisory
- http://www.kb.cert.org/vuls/id/970180 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.redhat.com/support/errata/RHSA-2009-0478.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securityfocus.com/bid/34740 vdb-entryx_refsource_BIDExploitThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1022139 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/cas/techalerts/TA09-133B.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2009/1189 vdb-entryx_refsource_VUPENBroken Link
- http://www.vupen.com/english/advisories/2009/1317 vdb-entryx_refsource_VUPENBroken Link
- https://access.redhat.com/security/cve/CVE-2009-1493 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=498322 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50146 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2009-1493
- https://www.cve.org/CVERecord?id=CVE-2009-1493
- https://www.exploit-db.com/exploits/8570 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 30, 2009
Updated Aug 7, 2024
Reserved Apr 30, 2009
Link CVE-2009-1493
CISA Vulnrichment
Updated n/a