CVE Vulnerabilities

CVE-2020-24439

Improper Verification of Cryptographic Signature

Published: Nov 05, 2020 | Modified: Sep 16, 2021
CVSS 3.x
2.8
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CVSS 2.x
1.2 LOW
AV:L/AC:H/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Acrobat Reader DC for macOS versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a security feature bypass. While the practical security impact is minimal, a defense-in-depth fix has been implemented to further harden the Adobe Reader update process.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Acrobat Adobe * 20.001.30005 (including)
Acrobat_dc Adobe * 17.011.30175 (including)
Acrobat_dc Adobe * 20.012.20048 (including)
Acrobat_reader Adobe * 20.001.30005 (including)
Acrobat_reader_dc Adobe * 17.011.30175 (including)
Acrobat_reader_dc Adobe * 20.012.20048 (including)

References