9.3

CVE-2013-0640

Warnung
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Acrobat Version >= 9.0 < 9.5.4
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Acrobat Version >= 10.0 < 10.1.6
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Acrobat Version >= 11.0 < 11.0.02
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Acrobat Reader Version >= 10.0 < 10.1.6
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Acrobat Reader Version >= 11.0 < 11.0.02
   Apple ≫ macOS X Version -
   Microsoft ≫ Windows Version -
Opensuse ≫ Opensuse Version 11.4
Opensuse ≫ Opensuse Version 12.1
Suse ≫ Linux Enterprise Desktop Version 10 Update sp4 SwEdition -
Suse ≫ Linux Enterprise Desktop Version 11 Update sp2
Redhat ≫ Enterprise Linux Eus Version 5.9
Redhat ≫ Enterprise Linux Eus Version 6.4
Adobe ≫ Acrobat Reader Version >= 9.0 < 9.5.4
   Apple ≫ macOS X Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -

03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Adobe Reader and Acrobat Memory Corruption Vulnerability

Schwachstelle

An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 86.98% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://security.gentoo.org/glsa/glsa-201308-03.xml
Third Party Advisory
http://blog.fireeye.com/research/2013/02/in-turn-its-pdf-time.html
Broken Link
http://blogs.adobe.com/psirt/2013/02/adobe-reader-and-acrobat-vulnerability-report.html
Broken Link
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00021.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00023.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00024.html
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2013-0551.html
Third Party Advisory
http://www.adobe.com/support/security/advisories/apsa13-02.html
Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb13-07.html
Broken Link
http://www.kb.cert.org/vuls/id/422807
Third Party Advisory
US Government Resource
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16406
Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0640
US Government Resource