PT-2015-2371 · Adobe · Reader Document Cloud+3
Abdulaziz Hariri
+1
·
Published
2015-10-13
·
Updated
2021-09-08
·
CVE-2015-6703
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Acrobat and Adobe Acrobat Document Cloud versions (affected versions not specified)
Adobe Reader and Adobe Reader Document Cloud versions (affected versions not specified)
Description
The issue is related to the
loadFlashMovie function in Adobe's PDF editing and viewing software, which has inadequate access control mechanisms. This can be exploited by a remote attacker to access protected information in the process memory by providing invalid arguments. A memory-leak issue in Adobe Acrobat and Reader allows attackers to affect the system.Recommendations
For Adobe Acrobat and Adobe Acrobat Document Cloud, update to a version that addresses the
loadFlashMovie function issue.
For Adobe Reader and Adobe Reader Document Cloud, update to a version that addresses the loadFlashMovie function issue.
As a temporary workaround, consider disabling the loadFlashMovie function until a patch is available.Fix
Information Disclosure
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Acrobat
Acrobat Document Cloud
Reader
Reader Document Cloud