PT-2014-1390 · Adobe · Reader+1

Publicado

2014-03-27

·

Atualizado

2014-05-19

·

CVE-2014-0511

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Reader version 11.0.06 Acrobat (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary code via unspecified vectors. It was demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014. The problem is related to a heap-based buffer overflow in Adobe Reader and an integer overflow in PDF417 barcode parsing.
Recommendations For Adobe Reader version 11.0.06, update to a version that contains a fix for this issue. For Acrobat, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00275
BDU:2015-00276
CVE-2014-0511
ZDI-14-131

Produtos afetados

Acrobat
Reader