CVE-2009-2993
Summary
| CVE | CVE-2009-2993 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-10-19 22:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath parameter in a crafted PDF file. NOTE: some of these details are obtained from third party information. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Acrobat | 7.0 | All | All | All |
| Application | Adobe | Acrobat | 7.0.1 | All | All | All |
| Application | Adobe | Acrobat | 7.0.2 | All | All | All |
| Application | Adobe | Acrobat | 7.0.3 | All | All | All |
| Application | Adobe | Acrobat | 7.0.4 | All | All | All |
| Application | Adobe | Acrobat | 7.0.5 | All | All | All |
| Application | Adobe | Acrobat | 7.0.6 | All | All | All |
| Application | Adobe | Acrobat | 7.0.7 | All | All | All |
| Application | Adobe | Acrobat | 7.0.8 | All | All | All |
| Application | Adobe | Acrobat | 7.0.9 | All | All | All |
| Application | Adobe | Acrobat | 7.1.0 | All | All | All |
| Application | Adobe | Acrobat | 7.1.1 | All | All | All |
| Application | Adobe | Acrobat | 7.1.3 | All | All | All |
| Application | Adobe | Acrobat | 8.0 | All | All | All |
| Application | Adobe | Acrobat | 8.1 | All | All | All |
| Application | Adobe | Acrobat | 8.1.1 | All | All | All |
| Application | Adobe | Acrobat | 8.1.2 | All | All | All |
| Application | Adobe | Acrobat | 8.1.3 | All | All | All |
| Application | Adobe | Acrobat | 8.1.4 | All | All | All |
| Application | Adobe | Acrobat | 8.1.6 | All | All | All |
| Application | Adobe | Acrobat | 9.0 | All | All | All |
| Application | Adobe | Acrobat | 9.1.1 | All | All | All |
| Application | Adobe | Acrobat | 9.1.2 | All | All | All |
| Application | Adobe | Acrobat | All | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.2 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.3 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.4 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.5 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.6 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.7 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.8 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.9 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.1.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.1.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.1.3 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.2 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.3 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.4 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.5 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.6 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1.2 | All | All | All |
| Application | Adobe | Acrobat Reader | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| US-CERT Technical Cyber Security Alert TA09-286B -- Adobe Reader and Acrobat Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Patch, US Government Resource |
| Adobe Reader and Acrobat Multiple Input Validation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - Adobe Acrobat and Adobe Reader Flaws Lets Remote Users Execute Arbitrary Code and Deny Service | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| RETIRED: Adobe Reader and Acrobat October 2009 Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Adobe - Security Bulletin APSB09-15 Security Updates Available for Adobe Reader and Acrobat | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| US-CERT Vulnerability Note VU#257117 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Patch, US Government Resource |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.