acroread: Multiple arbitrary code execution fixes in 8.1.7 (APSB09-15)
Published Oct 19, 2009
9.3
HIGHCVSS 2.0
EPSS 6.73%
Description
The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath parameter in a crafted PDF file. NOTE: some of these details are obtained from third party information.
Affected products
No data.
Configuration 1
- ≤ 9.1.3
- 7.0
- 7.0.1
- 7.0.2
- 7.0.3
- 7.0.4
- 7.0.5
- 7.0.6
- 7.0.7
- 7.0.8
- 7.0.9
- 7.1.0
- 7.1.1
- 7.1.3
- 8.0
- 8.1
- 8.1.1
- 8.1.2
- 8.1.3
- 8.1.4
- 8.1.6
- 9.0
- 9.1.1
- 9.1.2
Configuration 2
- ≤ 9.1.3
- 7.0
- 7.0.1
- 7.0.2
- 7.0.3
- 7.0.4
- 7.0.5
- 7.0.6
- 7.0.7
- 7.0.8
- 7.0.9
- 7.1.0
- 7.1.1
- 7.1.3
- 8.0
- 8.1
- 8.1.1
- 8.1.2
- 8.1.3
- 8.1.4
- 8.1.5
- 8.1.6
- 9.0
- 9.1
- 9.1.1
- 9.1.2
No data.
Extras for RHEL 3
acroread-0:8.1.7-1
Fixed · RHSA-2009:1499
Extras for RHEL 4
acroread-0:8.1.7-1.el4
Fixed · RHSA-2009:1499
Supplementary for Red Hat Enterprise Linux 5
acroread-0:8.1.7-1.el5
Fixed · RHSA-2009:1499
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 3 | acroread-0:8.1.7-1 | Fixed | RHSA-2009:1499 |
| Extras for RHEL 4 | acroread-0:8.1.7-1.el4 | Fixed | RHSA-2009:1499 |
| Supplementary for Red Hat Enterprise Linux 5 | acroread-0:8.1.7-1.el5 | Fixed | RHSA-2009:1499 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- http://securitytracker.com/id?1023007 vdb-entryx_refsource_SECTRACK
- http://www.adobe.com/support/security/bulletins/apsb09-15.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.kb.cert.org/vuls/id/257117 third-party-advisoryx_refsource_CERT-VNPatchUS Government Resource
- http://www.securityfocus.com/bid/36638 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/36664 vdb-entryx_refsource_BID
- http://www.us-cert.gov/cas/techalerts/TA09-286B.html third-party-advisoryx_refsource_CERTPatchUS Government Resource
- http://www.vupen.com/english/advisories/2009/2898 vdb-entryx_refsource_VUPENPatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-2993 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=528659 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-2993
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5822 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-2993
| Link | Providers | Tags |
|---|---|---|
| http://securitytracker.com/id?1023007 | vdb-entryx_refsource_SECTRACK | |
| http://www.adobe.com/support/security/bulletins/apsb09-15.html | x_refsource_CONFIRMPatchVendor Advisory | |
| http://www.kb.cert.org/vuls/id/257117 | third-party-advisoryx_refsource_CERT-VNPatchUS Government Resource | |
| http://www.securityfocus.com/bid/36638 | vdb-entryx_refsource_BID | |
| http://www.securityfocus.com/bid/36664 | vdb-entryx_refsource_BID | |
| http://www.us-cert.gov/cas/techalerts/TA09-286B.html | third-party-advisoryx_refsource_CERTPatchUS Government Resource | |
| http://www.vupen.com/english/advisories/2009/2898 | vdb-entryx_refsource_VUPENPatchVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2009-2993 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=528659 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-2993 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5822 | vdb-entrysignaturex_refsource_OVAL | |
| https://www.cve.org/CVERecord?id=CVE-2009-2993 |
Change history (0)
No recorded changes yet.