PT-2015-2367 · Adobe · Reader Document Cloud+3

Abdulaziz Hariri

+1

·

Publicado

2015-10-13

·

Atualizado

2021-09-08

·

CVE-2015-6699

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe Acrobat versions (affected versions not specified) Adobe Acrobat Document Cloud versions (affected versions not specified) Adobe Reader versions (affected versions not specified) Adobe Reader Document Cloud versions (affected versions not specified)
Description The issue is related to the addForegroundSprite function in Adobe's PDF editing and viewing software, which has inadequate access control mechanisms. This can be exploited by a remote attacker to access protected information in the process memory by providing invalid arguments. A memory-leak issue in Adobe Acrobat and Reader allows attackers to affect the system.
Recommendations For Adobe Acrobat, update to a version that addresses the addForegroundSprite function issue. For Adobe Acrobat Document Cloud, restrict access to the addForegroundSprite function until a patch is available. For Adobe Reader, avoid using the addForegroundSprite function in sensitive operations until the issue is resolved. For Adobe Reader Document Cloud, consider disabling the addForegroundSprite function as a temporary workaround until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Missing Release of Resource after Effective Lifetime

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-11732
CVE-2015-6699
ZDI-15-477

Produtos afetados

Acrobat
Acrobat Document Cloud
Reader
Reader Document Cloud