CERT-In Vulnerability Note
CIVN-2014-0282
Multiple Vulnerabilities in Adobe Reader and Adobe Acrobat
Original Issue Date:December 10, 2014
Severity Rating: HIGH
Systems Affected
- Adobe Reader XI (11.0.09) and earlier 11.x versions
- Adobe Reader X (10.1.12) and earlier 10.x versions
- Adobe Acrobat XI (11.0.09) and earlier 11.x versions
- Adobe Acrobat X (10.1.12) and earlier 10.x versions
Overview
Multiple vulnerabilities have been reported in Adobe Reader and Adobe Acrobat which could allow an unauthenticated remote attacker to execute arbitrary code or bypass security restrictions to take complete control of the targeted system.
Description
These vulnerabilities are due to memory corruption/use after free memory errors , heap based /integer buffer overflow s, time-of-check time-of-use (TOCTOU) race condition, improper implementation of Javascript API, improper handling of external XML entities, bypass same origin policy in Adobe reader /acrobat the way it handles crafted files.
An unauthenticated remote attacker could exploit these vulnerabilities by enticing users to open specially crafted file sent via email attachments that could allow remote attacker to execute arbitrary code on the targeted system or bypass security restrictions to take complete control of the affected system.
Solution
Apply appropriate patches as mentioned in Adobe Security Bulletin
APSB14-28
Vendor Information
Adobe
http://helpx.adobe.com/security/products/reader/apsb14-28.html
References
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=36705
Security Tracker
http://securitytracker.com/id/1031322
CVE Name
CVE-2014-8445
CVE-2014-8446
CVE-2014-8447
CVE-2014-8448
CVE-2014-8449
CVE-2014-8451
CVE-2014-8452
CVE-2014-8453
CVE-2014-8454
CVE-2014-8455
CVE-2014-8456
CVE-2014-8457
CVE-2014-8458
CVE-2014-8459
CVE-2014-8460
CVE-2014-8461
CVE-2014-9150
CVE-2014-9158
CVE-2014-9159
CVE-2014-9165
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|