PT-2016-1031 · Adobe · Acrobat+1

Jaanus

·

Published

2016-01-07

·

Updated

2016-12-07

·

CVE-2016-0936

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Reader (affected versions not specified) Adobe Acrobat (affected versions not specified)
Description The issue is caused by a buffer overflow in Adobe Reader and Acrobat, allowing a remote attacker to execute arbitrary code or cause a denial of service (memory corruption). A memory corruption vulnerability in these products enables attackers to execute code. The vulnerability is also related to out-of-bounds indexing in the JPEG2000 component.
Recommendations For Adobe Reader, update to a version that fixes the buffer overflow issue. For Adobe Acrobat, update to a version that fixes the buffer overflow issue. As a temporary workaround, consider disabling the JPEG2000 component in Adobe Reader and Acrobat until a patch is available. Restrict access to untrusted PDF files to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00097
CVE-2016-0936
ZDI-16-014

Affected Products

Acrobat
Reader