Adobe Acrobat and Reader CVE-2013-3351 Multiple Stack Buffer Overflow Vulnerabilities
BID:62429
Info
Adobe Acrobat and Reader CVE-2013-3351 Multiple Stack Buffer Overflow Vulnerabilities
| Bugtraq ID: | 62429 |
| Class: | Unknown |
| CVE: |
CVE-2013-3351 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2013 12:00AM |
| Updated: | Sep 10 2013 12:00AM |
| Credit: | Mateusz Jurczyk and Gynvael Coldwind of the Google Security Team |
| Vulnerable: |
Adobe Reader (for Windows) 11.0.3 Adobe Reader (for Windows) 11.0.2 Adobe Reader (for Windows) 10.1.7 Adobe Reader (for Windows) 10.1.6 Adobe Reader (for Windows) 10.1.5 Adobe Reader (for Windows) 10.0.1 Adobe Reader (for Macintosh) 11.0.3 Adobe Reader (for Macintosh) 11.0.2 Adobe Reader (for Macintosh) 10.1.7 Adobe Reader (for Macintosh) 10.1.6 Adobe Reader (for Macintosh) 10.1.5 Adobe Reader (for Macintosh) 10.0.1 Adobe Acrobat X (for Windows) 11.0.3 Adobe Acrobat (for Windows) 11.0.3 Adobe Acrobat (for Windows) 11.0.2 Adobe Acrobat (for Windows) 11.0.1 Adobe Acrobat (for Windows) 10.1.7 Adobe Acrobat (for Windows) 10.1.6 Adobe Acrobat (for Windows) 10.1.5 Adobe Acrobat (for Macintosh) 11.0.3 Adobe Acrobat (for Macintosh) 11.0.2 Adobe Acrobat (for Macintosh) 11.0.1 Adobe Acrobat (for Macintosh) 10.1.7 Adobe Acrobat (for Macintosh) 10.1.6 Adobe Acrobat (for Macintosh) 10.1.5 |
| Not Vulnerable: |
Adobe Reader XI (for Macintosh) 11.0.4 Adobe Reader X (for Windows) 10.1.8 Adobe Reader X (for Macintosh) 10.1.8 Adobe Reader (for Windows) 11.0.4 Adobe Acrobat XI (for Macintosh) 11.0.4 Adobe Acrobat X (for Windows) 10.1.8 Adobe Acrobat X (for Macintosh) 10.1.8 Adobe Acrobat (for Windows) 11.0.4 |
Discussion
Adobe Acrobat and Reader CVE-2013-3351 Multiple Stack Buffer Overflow Vulnerabilities
Adobe Acrobat and Reader are prone to multiple stack-based buffer-overflow vulnerabilities.
Attackers can exploit these issue to execute arbitrary code in the context of the user running the affected applications. Failed exploit attempts will likely cause denial-of-service conditions.
Note: These issues were previously discussed in BID 62293 (Adobe Acrobat and Reader APSB13-22 Multiple Remote Code Execution Vulnerabilities), but have been moved to their own record for better documentation.
Adobe Acrobat and Reader are prone to multiple stack-based buffer-overflow vulnerabilities.
Attackers can exploit these issue to execute arbitrary code in the context of the user running the affected applications. Failed exploit attempts will likely cause denial-of-service conditions.
Note: These issues were previously discussed in BID 62293 (Adobe Acrobat and Reader APSB13-22 Multiple Remote Code Execution Vulnerabilities), but have been moved to their own record for better documentation.
Exploit / POC
Adobe Acrobat and Reader CVE-2013-3351 Multiple Stack Buffer Overflow Vulnerabilities
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Acrobat and Reader CVE-2013-3351 Multiple Stack Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Adobe Acrobat and Reader CVE-2013-3351 Multiple Stack Buffer Overflow Vulnerabilities
References:
References:
- Acrobat Homepage (Adobe)
- Adobe Homepage (Adobe)
- Adobe Reader Homepage (Adobe)
- APSB13-22: Security updates available for Adobe Reader and Acrobat (Adobe)