PT-2017-1845 · Adobe · Reader Dc+2

Published

2017-04-06

·

Updated

2017-07-11

·

CVE-2017-3031

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier Adobe Acrobat versions prior to the fixed version are affected, however the exact fixed version is not specified
Description The issue is related to a memory address leak vulnerability in the XSLT engine of Adobe Acrobat and Reader. This vulnerability can be exploited by a remote attacker to cause a denial of service. The vulnerability is also described as a memory corruption issue that allows attackers to leak memory.
Recommendations For Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the XSLT engine in Adobe Acrobat and Reader until a patch is available. Restrict access to the XSLT namespace node to minimize the risk of exploitation. Avoid using nested variables in Adobe Reader DC until the issue is resolved.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01001
CVE-2017-3031
ZDI-17-256
ZDI-17-259

Affected Products

Acrobat
Acrobat Reader
Reader Dc