Security Intelligence Operations - Cisco Systems
Guest
 

Security Intelligence Operations


Adobe Acrobat and Reader Unspecified Memory Corruption Vulnerability

 
Security Activity BulletinPowered by Cisco Security IntelliShield Alert Manager

Threat Type:IntelliShield: Security Activity Bulletin
IntelliShield ID:18110
Version:1
First Published:May 01, 2009 09:57 AM EDT
Last Published:May 01, 2009 09:57 AM EDT
Port: Not Available
BugTraq ID:34768
 
Urgency: Unlikely Use
Credibility: Corroborated
Severity: Moderate Damage
 
Version Summary:

Adobe Acrobat and Reader contain a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the user. Updates are not available.



Description

Adobe Acrobat and Reader contain a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the targeted user.

This vulnerability was announced at a security conference in April 2009, and little technical detail is available to describe the flaw.

An unauthenticated, remote attacker could exploit the software flaw to cause memory corruption, which could be leveraged to execute arbitrary code. The vulnerability may be similar to recently released Adobe Acrobat vulnerabilities, such as those that are described in IntelliShield alerts 17665 and 17872.

No exploit code is not known to exist.

Adobe has not confirmed this vulnerability, and no updates are available.

 
Alert History
 

Initial Release



Product Sets
 
The security vulnerability applies to the following combinations of products.

Primary Products:
AdobeAcrobat Reader7.0 Base | 7.0.1 Base | 7.0.2 Base | 7.0.3 Base | 7.0.4 Base | 7.0.5 Base | 7.0.6 Base | 7.0.7 Base | 7.0.8 Base | 7.0.9 Base | 8.1 Base | 8.1.1 Base | 8.1.2 .1, Base | 8.1.3 Base | 8.1.4 Base
AdobeAdobe Acrobat Professional7.0 .0, .1, .2, .3, .4, .5, .6, .7, .8, .9 | 8.1 .0, .1, .2, .3, .4
AdobeAdobe Acrobat Standard7.0 Base | 7.0.1 Base | 7.0.2 Base | 7.0.3 Base | 7.0.4 Base | 7.0.5 Base | 7.0.6 Base | 7.0.7 Base | 7.0.8 Base | 7.0.9 Base | 8.1 Base | 8.1.1 Base | 8.1.2 Base | 8.1.3 Base | 8.1.4 Base

Associated Products:
N/A



LEGAL DISCLAIMER
The urgency and severity ratings of this alert are not tailored to individual users; users may value alerts differently based upon their network configurations and circumstances. THE ALERT, AND INFORMATION CONTAINED THEREIN, ARE PROVIDED ON AN "AS IS" BASIS AND DO NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE ALERT, AND INFORMATION CONTAINED THEREIN, OR MATERIALS LINKED FROM THE ALERT, IS AT YOUR OWN RISK. INFORMATION IN THIS ALERT AND ANY RELATED COMMUNICATIONS IS BASED ON OUR KNOWLEDGE AT THE TIME OF PUBLICATION AND IS SUBJECT TO CHANGE WITHOUT NOTICE. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE ALERTS AT ANY TIME.