PT-2016-2685 · Adobe · Acrobat+3

Steven Seeley

·

Publicado

2016-07-07

·

Atualizado

2016-11-28

·

CVE-2016-4266

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Reader versions (affected versions not specified) Adobe Acrobat versions (affected versions not specified) Adobe Reader Document Cloud versions (affected versions not specified) Adobe Acrobat Document Cloud versions (affected versions not specified)
Description The issue is caused by a buffer overflow in Adobe Reader and Adobe Acrobat, allowing a remote attacker to execute arbitrary code or cause a denial of service (memory corruption) through unknown vectors. It is also described as a memory corruption vulnerability that enables attackers to execute code. Additionally, there is an out-of-bounds read information disclosure vulnerability related to FlateDecode parsing in Adobe Reader DC.
Recommendations For Adobe Reader, update to a version that addresses the buffer overflow issue. For Adobe Acrobat, apply the necessary patch to fix the memory corruption vulnerability. For Adobe Reader Document Cloud, restrict access to untrusted PDF files until a fix is available. For Adobe Acrobat Document Cloud, consider disabling the FlateDecode parsing function as a temporary workaround until a patch is released. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-02077
CVE-2016-4266
ZDI-16-489

Produtos afetados

Acrobat
Acrobat Document Cloud
Reader
Reader Document Cloud