CVE Vulnerabilities

CVE-2009-1493

Published: Apr 30, 2009 | Modified: May 17, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.

Affected Software

Name Vendor Start Version End Version
Reader Adobe 8.1.4 (including) 8.1.4 (including)
Reader Adobe 9.1 (including) 9.1 (including)
Extras for RHEL 3 RedHat acroread-0:8.1.5-2 *
Extras for RHEL 4 RedHat acroread-0:8.1.5-1.el4 *
Supplementary for Red Hat Enterprise Linux 5 RedHat acroread-0:8.1.5-1.el5 *
Acroread Ubuntu dapper *
Acroread Ubuntu devel *
Acroread Ubuntu hardy *
Acroread Ubuntu intrepid *
Acroread Ubuntu jaunty *
Acroread Ubuntu karmic *

References