PT-2009-5333 · Adobe · Reader+1

Richard Van Eeden

·

Published

2009-10-19

·

Updated

2018-10-30

·

CVE-2009-2993

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Adobe Reader and Acrobat versions 7.x through 7.1.3 Adobe Reader and Acrobat versions 8.x through 8.1.6 Adobe Reader and Acrobat versions 9.x through 9.1
Description: The issue concerns the JavaScript for Acrobat API, which does not properly implement certain restrictions for unspecified JavaScript methods. This allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath parameter in a crafted PDF file.
Recommendations: For Adobe Reader and Acrobat versions 7.x through 7.1.3, update to version 7.1.4 or later. For Adobe Reader and Acrobat versions 8.x through 8.1.6, update to version 8.1.7 or later. For Adobe Reader and Acrobat versions 9.x through 9.1, update to version 9.2 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2993
RHSA-2009:1499

Affected Products

Acrobat
Reader