Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Reader Apsb09 15 | — | — | Apr 12, 2012 | Oct 13, 2009 |
| Gentoo Linux | — | Upgrade app-text/acroread. | Oct 30, 2017 | Oct 13, 2009 |
| Suse | — | Upgrade acroreadUpgrade acroread_ja | Feb 17, 2015 | Oct 13, 2009 |
| Ubuntu | — | Upgrade acroread | Nov 19, 2024 | Oct 13, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub