PT-2017-1857 · Adobe · Acrobat+1

Publicado

2017-04-06

·

Atualizado

2017-07-11

·

CVE-2017-3019

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier Adobe Acrobat versions prior to the fixed version are affected, but the exact versions are not specified
Description The issue is related to a memory corruption vulnerability in the Product Representation Compact (PRC) format parser. This vulnerability can be exploited to achieve arbitrary code execution. The vulnerability is caused by reading data beyond the boundaries of a specified buffer, allowing a remote attacker to execute arbitrary code.
Recommendations For Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier, update to a version that contains a fix for this vulnerability. For Adobe Acrobat, update to a version that contains a fix for this vulnerability, as the exact vulnerable versions are not specified. As a temporary workaround, consider disabling the PRC format parser in Adobe Acrobat and Reader until a patch is available.

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-01013
CVE-2017-3019
ZDI-17-249

Produtos afetados

Acrobat
Acrobat Reader