CVE Vulnerabilities

CVE-2024-49531

NULL Pointer Dereference

Published: Dec 10, 2024 | Modified: Jan 14, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Acrobat Adobe 20.001.30002 (including) 20.005.30748 (excluding)
Acrobat Adobe 24.001.30159 (including) 24.001.30225 (excluding)
Acrobat_dc Adobe 15.007.20033 (including) 24.005.20320 (excluding)
Acrobat_reader Adobe 20.001.30002 (including) 20.005.30748 (excluding)
Acrobat_reader_dc Adobe 15.007.20033 (including) 24.005.20320 (excluding)

Potential Mitigations

References