PT-2017-14396 · Adobe · Acrobat

Publicado

2017-11-14

·

Atualizado

2018-02-12

·

CVE-2017-16383

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Acrobat versions prior to 2017.012.20098 Adobe Acrobat versions prior to 2017.011.30066 Adobe Acrobat versions prior to 2015.006.30355 Adobe Acrobat versions prior to 11.0.22
Description The issue is related to a heap overflow vulnerability when processing a JPEG file embedded within an XPS document. This allows attackers to execute code remotely. The vulnerability is triggered by parsing a specifically crafted JPEG file, which leads to a heap-based buffer overflow.
Recommendations For versions prior to 2017.012.20098, update to a version later than 2017.012.20098 to resolve the issue. For versions prior to 2017.011.30066, update to a version later than 2017.011.30066 to resolve the issue. For versions prior to 2015.006.30355, update to a version later than 2015.006.30355 to resolve the issue. For versions prior to 11.0.22, update to a version later than 11.0.22 to resolve the issue. As a temporary workaround, consider disabling the processing of JPEG files embedded within XPS documents until a patch is available.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-16383
ZDI-17-900
ZDI-18-157

Produtos afetados

Acrobat