KLA10682
Multiple vulnerabilities in Adobe Acrobat and Reader

Обновлено: 18/06/2020
Дата обнаружения
13/10/2015
Уровень угрозы
Critical
Описание

Multiple serious vulnerabilities have been found in Adobe Acrobat and Reader. Malicious users can exploit these vulnerabilities to execute arbitrary code or obtain sensitive information.

Below is a complete list of vulnerabilities

  1. An unknown vulnerability can be exploited via specially designed print job to obtain sensitive information;
  2. Use-after-free vulnerability can be exploited to execute arbitrary code;
  3. An unknown vulnerability can be exploited via Format action to cause denial of service;
  4. Buffer overflow can be exploited to obtain sensitive information or execute arbitrary code;
  5. An unknown vulnerability can be exploited via data reading to obtain sensitive information;
  6. An unknown vulnerability related to JavaScript API can be exploited to bypass security restrictions.

Technical details

Vulnerability (1) can be triggered via launching print job on remote printer.

Vulnerability (3) can be triggered via using the Format action on unspecified fields.

Vulnerability (5) can be triggered via reading light object’s RGB data. This vulnerability leads to color objects information disclosure.

(6) related to ANSendForReview method.

Пораженные продукты

Adobe Acrobat  Reader X versions earlier than 10.1.16
Adobe Acrobat DC Continuous track versions earlier than 2015.009.20069
Adobe Acrobat Reader DC Continuous track versions earlier than 2015.009.20069
Adobe Acrobat DC Classic track versions earlier than 2015.006.30094
Adobe Acrobat Reader DC Classic track versions earlier than 2015.006.30094
Adobe Acrobat XI versions earlier than 11.0.13
Adobe Acrobat  Reader XI versions earlier than 11.0.13
Adobe Acrobat X versions earlier than 10.1.16

Решение

Update to the latest version
Get Adobe Reader

Первичный источник обнаружения
Adobe bulletin
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]
Связанные продукты
Adobe Reader X
Adobe Acrobat X
Adobe Reader XI
Adobe Acrobat XI
Adobe Acrobat Reader DC Continuous
Adobe Acrobat Reader DC Classic
Adobe Acrobat DC Continuous
Adobe Acrobat DC Classic
CVE-IDS
Эксплуатация

The following public exploits exists for this vulnerability:

https://www.exploit-db.com/exploits/38787

Узнай статистику распространения уязвимостей в твоем регионе