CVE-2009-3462
Summary
| CVE | CVE-2009-3462 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-10-19 22:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Unix, when Debug mode is enabled, allow attackers to execute arbitrary code via unspecified vectors, related to a "format bug." |
Risk And Classification
Primary CVSS: v2.0 5.1 from [email protected]
AV:N/AC:H/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:H/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Acrobat | 7.0 | All | All | All |
| Application | Adobe | Acrobat | 7.0.1 | All | All | All |
| Application | Adobe | Acrobat | 7.0.2 | All | All | All |
| Application | Adobe | Acrobat | 7.0.3 | All | All | All |
| Application | Adobe | Acrobat | 7.0.4 | All | All | All |
| Application | Adobe | Acrobat | 7.0.5 | All | All | All |
| Application | Adobe | Acrobat | 7.0.6 | All | All | All |
| Application | Adobe | Acrobat | 7.0.7 | All | All | All |
| Application | Adobe | Acrobat | 7.0.8 | All | All | All |
| Application | Adobe | Acrobat | 7.0.9 | All | All | All |
| Application | Adobe | Acrobat | 7.1.0 | All | All | All |
| Application | Adobe | Acrobat | 7.1.1 | All | All | All |
| Application | Adobe | Acrobat | 7.1.3 | All | All | All |
| Application | Adobe | Acrobat | 8.0 | All | All | All |
| Application | Adobe | Acrobat | 8.1 | All | All | All |
| Application | Adobe | Acrobat | 8.1.1 | All | All | All |
| Application | Adobe | Acrobat | 8.1.2 | All | All | All |
| Application | Adobe | Acrobat | 8.1.3 | All | All | All |
| Application | Adobe | Acrobat | 8.1.4 | All | All | All |
| Application | Adobe | Acrobat | 8.1.6 | All | All | All |
| Application | Adobe | Acrobat | 9.0 | All | All | All |
| Application | Adobe | Acrobat | 9.1.1 | All | All | All |
| Application | Adobe | Acrobat | 9.1.2 | All | All | All |
| Application | Adobe | Acrobat | All | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.2 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.3 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.4 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.5 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.6 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.7 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.8 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.0.9 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.1.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.1.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 7.1.3 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.2 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.3 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.4 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.5 | All | All | All |
| Application | Adobe | Acrobat Reader | 8.1.6 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.0 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1.1 | All | All | All |
| Application | Adobe | Acrobat Reader | 9.1.2 | All | All | All |
| Application | Adobe | Acrobat Reader | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| US-CERT Technical Cyber Security Alert TA09-286B -- Adobe Reader and Acrobat Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Patch, US Government Resource |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| SecurityTracker.com Archives - Adobe Acrobat and Adobe Reader Flaws Lets Remote Users Execute Arbitrary Code and Deny Service | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| RETIRED: Adobe Reader and Acrobat October 2009 Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Adobe - Security Bulletin APSB09-15 Security Updates Available for Adobe Reader and Acrobat | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.