PT-2016-1031 · Adobe · Acrobat+1
Jaanus
·
Published
2016-01-07
·
Updated
2016-12-07
·
CVE-2016-0936
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Reader (affected versions not specified)
Adobe Acrobat (affected versions not specified)
Description
The issue is caused by a buffer overflow in Adobe Reader and Acrobat, allowing a remote attacker to execute arbitrary code or cause a denial of service (memory corruption). A memory corruption vulnerability in these products enables attackers to execute code. The vulnerability is also related to out-of-bounds indexing in the JPEG2000 component.
Recommendations
For Adobe Reader, update to a version that fixes the buffer overflow issue.
For Adobe Acrobat, update to a version that fixes the buffer overflow issue.
As a temporary workaround, consider disabling the JPEG2000 component in Adobe Reader and Acrobat until a patch is available.
Restrict access to untrusted PDF files to minimize the risk of exploitation.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acrobat
Reader