Back

HIGH

acroread: Multiple arbitrary code execution fixes in 8.1.7 (APSB09-15)

Published Oct 19, 2009

Description

The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath parameter in a crafted PDF file. NOTE: some of these details are obtained from third party information.

Affected products

Remediation

No remediation recorded yet.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 19, 2009
Updated Aug 7, 2024
Reserved Aug 27, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Oct 13, 2009