PT-2015-2368 · Adobe · Reader Document Cloud+3
Abdulaziz Hariri
+1
·
Publicado
2015-10-13
·
Atualizado
2021-09-08
·
CVE-2015-6700
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Acrobat and Adobe Acrobat Document Cloud (affected versions not specified)
Adobe Reader and Adobe Reader Document Cloud (affected versions not specified)
Description
The issue is related to the
setBackground function in Adobe's PDF editing and viewing software, which has flaws in its access control mechanisms. This can be exploited by a remote attacker to access protected information in the process memory by setting invalid arguments. A memory-leak issue in Adobe Acrobat and Reader allows attackers to affect the system.Recommendations
For Adobe Acrobat and Adobe Acrobat Document Cloud, consider restricting access to the
setBackground function until a patch is available.
For Adobe Reader and Adobe Reader Document Cloud, avoid using the setBackground function in affected API endpoints until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Information Disclosure
Missing Release of Resource after Effective Lifetime
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Acrobat
Acrobat Document Cloud
Reader
Reader Document Cloud