CVE Vulnerabilities

CVE-2009-2979

Published: Oct 19, 2009 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 IMPORTANT
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 do not properly perform XMP-XML entity expansion, which allows remote attackers to cause a denial of service via a crafted document.

Affected Software

Name Vendor Start Version End Version
Acrobat Adobe * 9.1.3 (including)
Acrobat Adobe 7.0 (including) 7.0 (including)
Acrobat Adobe 7.0.1 (including) 7.0.1 (including)
Acrobat Adobe 7.0.2 (including) 7.0.2 (including)
Acrobat Adobe 7.0.3 (including) 7.0.3 (including)
Acrobat Adobe 7.0.4 (including) 7.0.4 (including)
Acrobat Adobe 7.0.5 (including) 7.0.5 (including)
Acrobat Adobe 7.0.6 (including) 7.0.6 (including)
Acrobat Adobe 7.0.7 (including) 7.0.7 (including)
Acrobat Adobe 7.0.8 (including) 7.0.8 (including)
Acrobat Adobe 7.0.9 (including) 7.0.9 (including)
Acrobat Adobe 7.1.0 (including) 7.1.0 (including)
Acrobat Adobe 7.1.1 (including) 7.1.1 (including)
Acrobat Adobe 7.1.3 (including) 7.1.3 (including)
Acrobat Adobe 8.0 (including) 8.0 (including)
Acrobat Adobe 8.1 (including) 8.1 (including)
Acrobat Adobe 8.1.1 (including) 8.1.1 (including)
Acrobat Adobe 8.1.2 (including) 8.1.2 (including)
Acrobat Adobe 8.1.3 (including) 8.1.3 (including)
Acrobat Adobe 8.1.4 (including) 8.1.4 (including)
Acrobat Adobe 8.1.6 (including) 8.1.6 (including)
Acrobat Adobe 9.0 (including) 9.0 (including)
Acrobat Adobe 9.1.1 (including) 9.1.1 (including)
Acrobat Adobe 9.1.2 (including) 9.1.2 (including)
Extras for RHEL 3 RedHat acroread-0:8.1.7-1 *
Extras for RHEL 4 RedHat acroread-0:8.1.7-1.el4 *
Supplementary for Red Hat Enterprise Linux 5 RedHat acroread-0:8.1.7-1.el5 *
Acroread Ubuntu dapper *
Acroread Ubuntu devel *
Acroread Ubuntu hardy *
Acroread Ubuntu intrepid *
Acroread Ubuntu jaunty *
Acroread Ubuntu karmic *
Acroread Ubuntu upstream *

References