PT-2015-2367 · Adobe · Reader Document Cloud+3
Abdulaziz Hariri
+1
·
Publicado
2015-10-13
·
Atualizado
2021-09-08
·
CVE-2015-6699
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Acrobat versions (affected versions not specified)
Adobe Acrobat Document Cloud versions (affected versions not specified)
Adobe Reader versions (affected versions not specified)
Adobe Reader Document Cloud versions (affected versions not specified)
Description
The issue is related to the
addForegroundSprite function in Adobe's PDF editing and viewing software, which has inadequate access control mechanisms. This can be exploited by a remote attacker to access protected information in the process memory by providing invalid arguments. A memory-leak issue in Adobe Acrobat and Reader allows attackers to affect the system.Recommendations
For Adobe Acrobat, update to a version that addresses the
addForegroundSprite function issue.
For Adobe Acrobat Document Cloud, restrict access to the addForegroundSprite function until a patch is available.
For Adobe Reader, avoid using the addForegroundSprite function in sensitive operations until the issue is resolved.
For Adobe Reader Document Cloud, consider disabling the addForegroundSprite function as a temporary workaround until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Information Disclosure
Missing Release of Resource after Effective Lifetime
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Acrobat
Acrobat Document Cloud
Reader
Reader Document Cloud