CVE Vulnerabilities

CVE-2021-21057

NULL Pointer Dereference

Published: Feb 11, 2021 | Modified: Sep 08, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a null pointer dereference vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker could leverage this vulnerability to achieve denial of service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Acrobat Adobe 17.0 (including) 17.011.30188 (including)
Acrobat Adobe 20.0 (including) 20.001.30018 (including)
Acrobat_dc Adobe * 20.013.20074 (including)
Acrobat_reader Adobe 17.0 (including) 17.011.30188 (including)
Acrobat_reader Adobe 20.0 (including) 20.001.300183 (including)
Acrobat_reader_dc Adobe * 20.013.20074 (including)

Potential Mitigations

References