CERT-In Advisory
CIAD-2018-0028
Multiple Vulnerabilities in Adobe Acrobat and Reader
Original Issue Date: October 09, 2018
Severity Rating: High
Software Affected
- Adobe Acrobat DC 2018.011.20063 and prior versions
- Adobe Acrobat Reader DC 2018.011.20063 and prior versions
- Adobe Acrobat 2017 2017.011.30102 and prior versions
- Adobe Acrobat Reader 2017 2017.011.30102 and prior versions
- Adobe Acrobat DC 2015.006.30452 and prior versions
- Adobe Acrobat Reader DC 2015.006.30452 and prior versions
Overview
Multiple Vulnerabilities have been reported in Adobe Acrobat and Acrobat Reader which could allow a remote attacker to execute arbitrary code, obtain sensitive information and gain elevated privileges on a targeted system.
Description
These vulnerabilities are caused due to errors in the affected software namely Out-of-bounds write ,Out-of-bounds read, Heap Overflow, Use After Free, Type Confusion, Stack Overflow, Double Free, Integer Overflow, Buffer Errors, Untrusted pointer dereference, Untrusted pointer dereference, Security Bypass issues.
A remote attacker could exploit this vulnerability by installing malware without the victim's knowledge and take control over the affected system. Successful exploitation of these vulnerabilities that allow a remote attacker to execute arbitrary code, obtain sensitive information and gain elevated privileges on a targeted system.
Solution
Apply appropriate updates as mentioned in the
Adobe Security Advisory APSB18-30.html
Vendor Information
Adobe
https://helpx.adobe.com/security/products/acrobat/apsb18-30.html
References
Adobe
https://helpx.adobe.com/security/products/acrobat/apsb18-30.html
Securitytracker
https://securitytracker.com/id/1041809
Securityfocus
https://www.securityfocus.com/bid/105444
CVE Name
CVE-2018-15955
CVE-2018-15954
CVE-2018-15952
CVE-2018-15945
CVE-2018-15944
CVE-2018-15941
CVE-2018-15940
CVE-2018-15939
CVE-2018-15938
CVE-2018-15936
CVE-2018-15935
CVE-2018-15934
CVE-2018-15933
CVE-2018-15929
CVE-2018-15928
CVE-2018-12868
CVE-2018-12865
CVE-2018-12864
CVE-2018-12862
CVE-2018-12861
CVE-2018-12860
CVE-2018-12759
CVE-2018-15956
CVE-2018-15953
CVE-2018-15950
CVE-2018-15949
CVE-2018-15948
CVE-2018-15947
CVE-2018-15946
CVE-2018-15943
CVE-2018-15942
CVE-2018-15932
CVE-2018-15927
CVE-2018-15926
CVE-2018-15925
CVE-2018-15923
CVE-2018-15922
CVE-2018-12880
CVE-2018-12879
CVE-2018-12878
CVE-2018-12875
CVE-2018-12874
CVE-2018-12873
CVE-2018-12872
CVE-2018-12871
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|