Overview
Description
The Adobe Acrobat ActiveX control has a buffer overflow in the setview method. Because the control is marked safe-for-scripting, this vulnerability can be exploited via a web page if the user has the vulnerable control installed. This control is implemtned in the file pdf.ocx and has a ClassID of {CA8A9780-280D-11CF-A24D-444553540000}. The control can also be referenced as PDF.PdfCtrl.1. |
Impact
An attacker may exploit the buffer overflow to execute arbitrary commands on the system running the vulnerable control. Because the control is marked safe-for-scripting, an attacker may be able to launch this attack when you visit a web page. |
Solution
Upgrade to a newer version of Adobe Acrobat |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This document was written by Cory F Cohen.
Other Information
CVE IDs: | CVE-1999-1484 |
Severity Metric: | 16.83 |
Date Public: | 1999-09-30 |
Date First Published: | 2000-11-02 |
Date Last Updated: | 2000-11-02 22:07 UTC |
Document Revision: | 4 |