acroread: script injection vulnerability (APSB10-02)
Published Jan 13, 2010
10.0
HIGHCVSS 2.0
EPSS 7.73%
Description
The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers.
Affected products
No data.
Configuration 1
- ≤ 9.2
- 3.0
- 3.1
- 4.0
- 4.0.5
- 4.0.5a
- 4.0.5c
- 5.0
- 5.0.5
- 5.0.6
- 5.0.10
- 6.0
- 6.0.1
- 6.0.2
- 6.0.3
- 6.0.4
- 6.0.5
- 6.0.6
- 7.0
- 7.0.1
- 7.0.2
- 7.0.3
- 7.0.4
- 7.0.5
- 7.0.6
- 7.0.7
- 7.0.8
- 7.0.9
- 7.1.0
- 7.1.1
- 7.1.2
- 7.1.3
- 7.1.4
- 8.0
- 8.1
- 8.1.1
- 8.1.2
- 8.1.3
- 8.1.4
- 8.1.5
- 8.1.6
- 8.1.7
- 9.0
- 9.1
- 9.1.1
- 9.1.2
- 9.1.3
Configuration 2
- ≤ 9.2
- 3.0
- 3.01
- 3.02
- 4.0
- 4.0.5
- 4.0.5a
- 4.0.5c
- 4.5
- 5.0
- 5.0.5
- 5.0.6
- 5.0.7
- 5.0.9
- 5.0.10
- 5.0.11
- 5.1
- 6.0
- 6.0.1
- 6.0.2
- 6.0.3
- 6.0.4
- 6.0.5
- 7.0
- 7.0.1
- 7.0.2
- 7.0.3
- 7.0.4
- 7.0.5
- 7.0.6
- 7.0.7
- 7.0.8
- 7.0.9
- 7.1.0
- 7.1.1
- 7.1.2
- 7.1.3
- 8.0
- 8.1
- 8.1.1
- 8.1.2
- 8.1.4
- 8.1.5
- 8.1.6
- 8.1.7
- 9.0
- 9.1
- 9.1.1
- 9.1.2
- 9.1.3
No data.
Extras for RHEL 3
acroread-0:9.3-3
Fixed · RHSA-2010:0060
Extras for RHEL 4
acroread-0:9.3-1.el4
Fixed · RHSA-2010:0038
Supplementary for Red Hat Enterprise Linux 5
acroread-0:9.3-1.el5
Fixed · RHSA-2010:0037
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 3 | acroread-0:9.3-3 | Fixed | RHSA-2010:0060 |
| Extras for RHEL 4 | acroread-0:9.3-1.el4 | Fixed | RHSA-2010:0038 |
| Supplementary for Red Hat Enterprise Linux 5 | acroread-0:9.3-1.el5 | Fixed | RHSA-2010:0037 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (18)
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/38138 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/38215 third-party-advisoryx_refsource_SECUNIA
- http://www.adobe.com/support/security/bulletins/apsb10-02.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.packetstormsecurity.org/1001-exploits/SS-2010-001.txt x_refsource_MISC
- http://www.redhat.com/support/errata/RHSA-2010-0060.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/37763 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1023446 vdb-entryx_refsource_SECTRACK
- http://www.stratsec.net/files/SS-2010-001_Stratsec_Acrobat_Script_Injection_Security_Advisory_v1.0.pdf x_refsource_MISC
- http://www.us-cert.gov/cas/techalerts/TA10-013A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2010/0103 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-3956 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=554296 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-3927 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55554 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-3956
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8327 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-3956
Change history (0)
No recorded changes yet.