RETIRED: Adobe Acrobat and Reader 'util.printf()' Remote Buffer Overflow Vulnerability
BID:32091
Info
RETIRED: Adobe Acrobat and Reader 'util.printf()' Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 32091 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2992 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2008 12:00AM |
| Updated: | Nov 04 2008 04:45PM |
| Credit: | Dyon Balding |
| Vulnerable: |
Adobe Reader 8.1.2 Adobe Acrobat Standard 8.1.2 |
| Not Vulnerable: | |
Discussion
RETIRED: Adobe Acrobat and Reader 'util.printf()' Remote Buffer Overflow Vulnerability
Adobe Acrobat and Reader are prone to a remote buffer-overflow vulnerability because they fail to properly bounds-check user-supplied data before copying it to an insufficiently sized buffer.
Exploiting this issue may allow attackers to corrupt memory and execute arbitrary machine code in the context of users running the affected application. Failed exploits will likely cause denial-of-service conditions.
The issue affects Adobe Acrobat and Reader versions 8.1.2; other versions may also be vulnerable.
This BID is being retired as a duplicate of BID 30035 (Adobe Reader 'util.print()' JavaScript Function Stack Buffer Overflow Vulnerability)
Adobe Acrobat and Reader are prone to a remote buffer-overflow vulnerability because they fail to properly bounds-check user-supplied data before copying it to an insufficiently sized buffer.
Exploiting this issue may allow attackers to corrupt memory and execute arbitrary machine code in the context of users running the affected application. Failed exploits will likely cause denial-of-service conditions.
The issue affects Adobe Acrobat and Reader versions 8.1.2; other versions may also be vulnerable.
This BID is being retired as a duplicate of BID 30035 (Adobe Reader 'util.print()' JavaScript Function Stack Buffer Overflow Vulnerability)
Exploit / POC
RETIRED: Adobe Acrobat and Reader 'util.printf()' Remote Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: Adobe Acrobat and Reader 'util.printf()' Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Reportedly, the vendor will shortly release fixes, but Symantec did not confirm this information.
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Reportedly, the vendor will shortly release fixes, but Symantec did not confirm this information.
References
RETIRED: Adobe Acrobat and Reader 'util.printf()' Remote Buffer Overflow Vulnerability
References:
References:
- Adobe Homepage (Adobe)
- Secunia Research: Adobe Acrobat/Reader 'util.printf()' Buffer Overflow (Secunia Research)