Back

HIGH

acroread: multiple code execution flaws (APSB13-02)

Published Jan 10, 2013

Description

Heap-based buffer overflow in the XSLT engine in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing an XSL file that triggers memory corruption when the lang function processes XML data with a crafted node-set.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 10, 2013
Updated Aug 6, 2024
Reserved Mar 8, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Jan 8, 2013