PT-2008-1161 · Adobe · Reader+1

Debasis Mohanty

+1

·

Publicado

2008-01-21

·

Atualizado

2025-10-22

·

CVE-2008-2992

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Acrobat and Reader versions 8.1.2 and earlier
Description The issue is related to a stack-based buffer overflow in Adobe Acrobat and Reader, allowing remote attackers to execute arbitrary code via a PDF file that calls the util.printf() JavaScript function with a crafted format string argument. This is due to incorrect input validation, which can lead to a buffer overflow in memory when the util.printf() function is called. The exploitation of this issue can allow a remote attacker to execute arbitrary code by opening a specially crafted malicious PDF file or link.
Recommendations For Adobe Acrobat and Reader versions 8.1.2 and earlier, consider disabling the util.printf() JavaScript function as a temporary workaround until a patch is available. Restrict access to PDF files from untrusted sources to minimize the risk of exploitation.

Exploit

Correção

Memory Corruption

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-04091
CVE-2008-2992
RHSA-2008:0974

Produtos afetados

Acrobat
Reader