9.3

CVE-2008-4817

The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, triggering heap corruption.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Acrobat Update unknown Edition 3d Version <= 8.1.2
Adobe ≫ Acrobat Update unknown Edition professional Version <= 8.1.2
Adobe ≫ Acrobat Update unknown Edition standard Version <= 8.1.2
Adobe ≫ Acrobat Version 8.1.1
Adobe ≫ Acrobat Version 8.1.1 Update unknown Edition 3d
Adobe ≫ Acrobat Version 8.1.1 Update unknown Edition professional
Adobe ≫ Acrobat Version 8.1.1 Update unknown Edition standard
Adobe ≫ Acrobat Reader Version <= 8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.92% 0.946
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html
http://download.oracle.com/sunalerts/1019937.1.html
http://secunia.com/advisories/32700
http://secunia.com/advisories/32872
http://www.adobe.com/support/security/bulletins/apsb08-19.html
Patch
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0974.html
http://www.securitytracker.com/id?1021140
http://www.us-cert.gov/cas/techalerts/TA08-309A.html
US Government Resource
http://www.vupen.com/english/advisories/2008/3001
http://www.vupen.com/english/advisories/2009/0098
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=756
http://osvdb.org/49541