PT-2003-1396 · Adobe · Acrobat Reader

Vladimir Katalov

·

Published

2003-07-17

·

Updated

2008-09-05

·

CVE-2003-0142

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Adobe Acrobat Reader version 6
Description: The issue allows attackers to cause Adobe Acrobat Reader to enter Certified mode and run untrusted plugins by modifying the CTIsCertifiedMode function under certain circumstances when the "Certified plug-ins only" option is disabled. This can occur when Adobe Acrobat Reader loads plug-ins with signatures used for older versions of Acrobat.
Recommendations: For Adobe Acrobat Reader version 6, consider disabling the CTIsCertifiedMode function as a temporary workaround until a patch is available. Additionally, enabling the "Certified plug-ins only" option can help minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0142

Affected Products

Acrobat Reader