CVE Vulnerabilities

CVE-2009-1492

Published: Apr 30, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.

Affected Software

NameVendorStart VersionEnd Version
AcrobatAdobe7.0 (including)7.1.1 (including)
AcrobatAdobe8.0 (including)8.1.4 (including)
AcrobatAdobe9.0 (including)9.1 (including)
Extras for RHEL 3RedHatacroread-0:8.1.5-2*
Extras for RHEL 4RedHatacroread-0:8.1.5-1.el4*
Supplementary for Red Hat Enterprise Linux 5RedHatacroread-0:8.1.5-1.el5*
AcroreadUbuntudapper*
AcroreadUbuntudevel*
AcroreadUbuntuhardy*
AcroreadUbuntuintrepid*
AcroreadUbuntujaunty*
AcroreadUbuntukarmic*

References