Overview
Adobe Reader and Acrobat 11.0.01 and earlier, 10.1.5 and earlier, and 9.5.3 and earlier contain memory corruption vulnerabilities.
Description
The Adobe security bulletin APSB13-07 states: Adobe has released security updates for Adobe Reader and Acrobat XI (11.0.01 and earlier) for Windows and Macintosh, X (10.1.5 and earlier) for Windows and Macintosh, 9.5.3 and earlier 9.x versions for Windows and Macintosh, and Adobe Reader 9.5.3 and earlier 9.x versions for Linux. These updates address vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system. |
Impact
A remote attacker may be able to cause a denial of service or execute arbitrary code on the system in the context of the user running the Adobe product. |
Solution
Apply an Update |
Enable Protected View |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Temporal | 8.1 | E:H/RL:OF/RC:C |
Environmental | 8.3 | CDP:L/TD:H/CR:ND/IR:ND/AR:ND |
References
- https://www.adobe.com/support/security/bulletins/apsb13-07.html
- https://www.adobe.com/support/security/advisories/apsa13-02.html
- https://www.adobe.com/devnet-docs/acrobatetk/tools/AppSec/protectedview.html
- http://blogs.mcafee.com/mcafee-labs/digging-into-the-sandbox-escape-technique-of-the-recent-pdf-exploit
Acknowledgements
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2013-0640, CVE-2013-0641 |
Date Public: | 2013-02-13 |
Date First Published: | 2013-02-14 |
Date Last Updated: | 2014-07-30 06:41 UTC |
Document Revision: | 17 |