Adobe Acrobat and Reader CVE-2013-3358 Heap Buffer Overflow Vulnerability
BID:62430
Info
Adobe Acrobat and Reader CVE-2013-3358 Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 62430 |
| Class: | Unknown |
| CVE: |
CVE-2013-3358 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2013 12:00AM |
| Updated: | Sep 10 2013 12:00AM |
| Credit: | vulnazoid through HP's Zero Day Initiative |
| Vulnerable: |
Adobe Reader (for Windows) 11.0.3 Adobe Reader (for Windows) 11.0.2 Adobe Reader (for Windows) 10.1.7 Adobe Reader (for Windows) 10.1.6 Adobe Reader (for Windows) 10.1.5 Adobe Reader (for Windows) 10.0.1 Adobe Reader (for Macintosh) 11.0.3 Adobe Reader (for Macintosh) 11.0.2 Adobe Reader (for Macintosh) 10.1.7 Adobe Reader (for Macintosh) 10.1.6 Adobe Reader (for Macintosh) 10.1.5 Adobe Reader (for Macintosh) 10.0.1 Adobe Acrobat X (for Windows) 11.0.3 Adobe Acrobat (for Windows) 11.0.3 Adobe Acrobat (for Windows) 11.0.2 Adobe Acrobat (for Windows) 11.0.1 Adobe Acrobat (for Windows) 10.1.7 Adobe Acrobat (for Windows) 10.1.6 Adobe Acrobat (for Windows) 10.1.5 Adobe Acrobat (for Macintosh) 11.0.3 Adobe Acrobat (for Macintosh) 11.0.2 Adobe Acrobat (for Macintosh) 11.0.1 Adobe Acrobat (for Macintosh) 10.1.7 Adobe Acrobat (for Macintosh) 10.1.6 Adobe Acrobat (for Macintosh) 10.1.5 |
| Not Vulnerable: |
Adobe Reader XI (for Macintosh) 11.0.4 Adobe Reader X (for Windows) 10.1.8 Adobe Reader X (for Macintosh) 10.1.8 Adobe Reader (for Windows) 11.0.4 Adobe Acrobat XI (for Macintosh) 11.0.4 Adobe Acrobat X (for Windows) 10.1.8 Adobe Acrobat X (for Macintosh) 10.1.8 Adobe Acrobat (for Windows) 11.0.4 |
Discussion
Adobe Acrobat and Reader CVE-2013-3358 Heap Buffer Overflow Vulnerability
Adobe Acrobat and Reader are prone to a heap-based buffer-overflow vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the affected applications. Failed exploit attempts will likely cause a denial-of-service condition.
Note: This issue was previously discussed in BID 62293 (Adobe Acrobat and Reader APSB13-22 Multiple Remote Code Execution Vulnerabilities), but has been moved to its own record for better documentation.
Adobe Acrobat and Reader are prone to a heap-based buffer-overflow vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the affected applications. Failed exploit attempts will likely cause a denial-of-service condition.
Note: This issue was previously discussed in BID 62293 (Adobe Acrobat and Reader APSB13-22 Multiple Remote Code Execution Vulnerabilities), but has been moved to its own record for better documentation.
Exploit / POC
Adobe Acrobat and Reader CVE-2013-3358 Heap Buffer Overflow Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Acrobat and Reader CVE-2013-3358 Heap Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Adobe Acrobat and Reader CVE-2013-3358 Heap Buffer Overflow Vulnerability
References:
References: