PT-2014-1390 · Adobe · Reader+1

Published

2014-03-27

·

Updated

2014-05-19

·

CVE-2014-0511

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Reader version 11.0.06 Acrobat (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary code via unspecified vectors. It was demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014. The problem is related to a heap-based buffer overflow in Adobe Reader and an integer overflow in PDF417 barcode parsing.
Recommendations For Adobe Reader version 11.0.06, update to a version that contains a fix for this issue. For Acrobat, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00275
BDU:2015-00276
CVE-2014-0511
ZDI-14-131

Affected Products

Acrobat
Reader