PT-2006-6865 · Adobe · Acropdf Activex+1
Publicado
2006-12-03
·
Atualizado
2018-10-17
·
CVE-2006-6236
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Reader versions 7.0 through 7.0.8
Description
The issue allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the
src, setPageMode, setLayoutMode, and setNamedDest methods in an AcroPDF ActiveX control.Recommendations
For Adobe Reader versions 7.0 through 7.0.8, consider disabling the AcroPDF ActiveX control as a temporary workaround until a patch is available. Restrict access to the
src, setPageMode, setLayoutMode, and setNamedDest methods to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Acropdf Activex
Reader