Adobe Reader and Acrobat Unspecified Cross Domain Scripting Vulnerability
BID:48255
Info
Adobe Reader and Acrobat Unspecified Cross Domain Scripting Vulnerability
| Bugtraq ID: | 48255 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2011-2101 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2011 12:00AM |
| Updated: | Jun 20 2013 09:38AM |
| Credit: | Billy Rios from the Google Security Team |
| Vulnerable: |
Adobe Reader 9.3.4 Adobe Reader 9.3.3 Adobe Reader 9.3.2 Adobe Reader 9.3.1 Adobe Reader 9.1.3 Adobe Reader 9.1.2 Adobe Reader 9.1.1 Adobe Reader 8.2.6 Adobe Reader 8.2.5 Adobe Reader 8.2.4 Adobe Reader 8.2.3 Adobe Reader 8.2.2 Adobe Reader 8.2.1 Adobe Reader 8.1.7 Adobe Reader 8.1.6 Adobe Reader 8.1.5 Adobe Reader 8.1.4 Adobe Reader 8.1.3 Adobe Reader 8.1.2 Adobe Reader 8.1.1 Adobe Reader 9.4.4 Adobe Reader 9.4.3 Adobe Reader 9.4.2 Adobe Reader 9.4.1 Adobe Reader 9.4 Adobe Reader 9.3 Adobe Reader 9.2 Adobe Reader 9.1 Adobe Reader 9 Adobe Reader 9 Adobe Reader 8.2 Adobe Reader 8.1.2 Security Updat Adobe Reader 8.1 Adobe Reader 8.0 Adobe Reader 8 Adobe Reader 10.0.3 Adobe Reader 10.0.2 Adobe Reader 10.0.1 Adobe Reader 10.0 |
| Not Vulnerable: |
Adobe Reader 9.4.5 Adobe Reader 8.3 |
Discussion
Adobe Reader and Acrobat Unspecified Cross Domain Scripting Vulnerability
Adobe Reader and Acrobat are prone to an unspecified cross-domain scripting vulnerability.
A remote attacker can exploit this vulnerability to bypass the same-origin policy, execute arbitrary script code and obtain potentially sensitive information, or launch spoofing attacks against other sites.
Adobe Reader and Acrobat versions prior to 10.1 are affected.
Adobe Reader and Acrobat are prone to an unspecified cross-domain scripting vulnerability.
A remote attacker can exploit this vulnerability to bypass the same-origin policy, execute arbitrary script code and obtain potentially sensitive information, or launch spoofing attacks against other sites.
Adobe Reader and Acrobat versions prior to 10.1 are affected.
Exploit / POC
Adobe Reader and Acrobat Unspecified Cross Domain Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.
Solution / Fix
Adobe Reader and Acrobat Unspecified Cross Domain Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Adobe Reader and Acrobat Unspecified Cross Domain Scripting Vulnerability
References:
References:
- Acrobat Homepage (Adobe)
- Adobe Reader Homepage (Adobe)
- APSB11-16 Security updates available for Adobe Reader and Acrobat (Adobe)