HIGH
acroread: local privilege escalation flaw (APSB13-02)
Published Jan 10, 2013
7.2
HIGHCVSS 2.0
EPSS 0.67%
Description
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows local users to gain privileges via unknown vectors.
Affected products
No data.
Configuration 1
OR
- 9.0
- 9.0
- 9.1
- 9.1
- 9.1.1
- 9.1.1
- 9.1.2
- 9.1.3
- 9.1.3
- 9.2
- 9.2
- 9.3
- 9.3
- 9.3.1
- 9.3.1
- 9.3.2
- 9.3.2
- 9.3.3
- 9.3.4
- 9.3.4
- 9.4
- 9.4.1
- 9.4.1
- 9.4.2
- 9.4.2
- 9.4.3
- 9.4.3
- 9.4.4
- 9.4.4
- 9.4.5
- 9.4.5
- 9.4.6
- 9.4.6
- 9.4.7
- 9.5
- 9.5.1
- 9.5.2
Configuration 2
OR
- 9.0
- 9.1
- 9.1.1
- 9.1.2
- 9.1.3
- 9.2
- 9.3
- 9.3.1
- 9.3.2
- 9.3.3
- 9.3.4
- 9.4
- 9.4.1
- 9.4.2
- 9.4.3
- 9.4.4
- 9.4.5
- 9.4.6
- 9.4.7
- 9.5
- 9.5.1
- 9.5.2
Configuration 3
OR
- 10.0
- 10.0
- 10.0.1
- 10.0.1
- 10.0.2
- 10.0.3
- 10.1
- 10.1.1
- 10.1.2
- 10.1.3
- 10.1.4
Configuration 4
OR
- 10.0
- 10.0.1
- 10.0.2
- 10.0.3
- 10.1
- 10.1.1
- 10.1.2
- 10.1.3
- 10.1.4
Configuration 6
- 11.0
No data.
Red Hat Enterprise Linux 5
acroread
Not affected
Red Hat Enterprise Linux 6
acroread
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | acroread | Not affected | n/a |
| Red Hat Enterprise Linux 6 | acroread | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not Vulnerable. This issue does not affect the version of acroread as shipped with Red Hat Enterprise Linux 5 and 6.
Weaknesses (0)
No CWE recorded.
References (11)
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00004.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00005.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-01/msg00028.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-01/msg00081.html vendor-advisoryx_refsource_SUSE
- http://security.gentoo.org/glsa/glsa-201308-03.xml vendor-advisoryx_refsource_GENTOO
- http://www.adobe.com/support/security/bulletins/apsb13-02.html x_refsource_CONFIRMPatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2013-0627 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=893236 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-0627
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16154 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2013-0627
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00004.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00005.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-updates/2013-01/msg00028.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-updates/2013-01/msg00081.html | vendor-advisoryx_refsource_SUSE | |
| http://security.gentoo.org/glsa/glsa-201308-03.xml | vendor-advisoryx_refsource_GENTOO | |
| http://www.adobe.com/support/security/bulletins/apsb13-02.html | x_refsource_CONFIRMPatchVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2013-0627 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=893236 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-0627 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16154 | vdb-entrysignaturex_refsource_OVAL | |
| https://www.cve.org/CVERecord?id=CVE-2013-0627 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Jan 10, 2013
Updated Aug 6, 2024
Reserved Dec 18, 2012
Link CVE-2013-0627
CISA Vulnrichment
Updated n/a