Adobe Acrobat and Reader CVE-2013-3354 Unspecified Memory Corruption Vulnerability
BID:62432
Info
Adobe Acrobat and Reader CVE-2013-3354 Unspecified Memory Corruption Vulnerability
| Bugtraq ID: | 62432 |
| Class: | Unknown |
| CVE: |
CVE-2013-3354 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2013 12:00AM |
| Updated: | Sep 10 2013 12:00AM |
| Credit: | Mateusz Jurczyk and Gynvael Coldwind of the Google Security Team |
| Vulnerable: |
Adobe Reader (for Windows) 11.0.3 Adobe Reader (for Windows) 11.0.2 Adobe Reader (for Windows) 10.1.7 Adobe Reader (for Windows) 10.1.6 Adobe Reader (for Windows) 10.1.5 Adobe Reader (for Windows) 10.0.1 Adobe Reader (for Macintosh) 11.0.3 Adobe Reader (for Macintosh) 11.0.2 Adobe Reader (for Macintosh) 10.1.7 Adobe Reader (for Macintosh) 10.1.6 Adobe Reader (for Macintosh) 10.1.5 Adobe Reader (for Macintosh) 10.0.1 Adobe Acrobat X (for Windows) 11.0.3 Adobe Acrobat (for Windows) 11.0.3 Adobe Acrobat (for Windows) 11.0.2 Adobe Acrobat (for Windows) 11.0.1 Adobe Acrobat (for Windows) 10.1.7 Adobe Acrobat (for Windows) 10.1.6 Adobe Acrobat (for Windows) 10.1.5 Adobe Acrobat (for Macintosh) 11.0.3 Adobe Acrobat (for Macintosh) 11.0.2 Adobe Acrobat (for Macintosh) 11.0.1 Adobe Acrobat (for Macintosh) 10.1.7 Adobe Acrobat (for Macintosh) 10.1.6 Adobe Acrobat (for Macintosh) 10.1.5 |
| Not Vulnerable: |
Adobe Reader XI (for Macintosh) 11.0.4 Adobe Reader X (for Windows) 10.1.8 Adobe Reader X (for Macintosh) 10.1.8 Adobe Reader (for Windows) 11.0.4 Adobe Acrobat XI (for Macintosh) 11.0.4 Adobe Acrobat X (for Windows) 10.1.8 Adobe Acrobat X (for Macintosh) 10.1.8 Adobe Acrobat (for Windows) 11.0.4 |
Discussion
Adobe Acrobat and Reader CVE-2013-3354 Unspecified Memory Corruption Vulnerability
Adobe Acrobat and Reader are prone to an unspecified memory-corruption vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the affected applications. Failed exploit attempts will likely cause a denial-of-service condition.
Note: This issue is previously discussed in BID 62293 (Adobe Acrobat and Reader APSB13-22 Multiple Remote Code Execution Vulnerabilities), but has been moved to its own record for better documentation.
Adobe Acrobat and Reader are prone to an unspecified memory-corruption vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the affected applications. Failed exploit attempts will likely cause a denial-of-service condition.
Note: This issue is previously discussed in BID 62293 (Adobe Acrobat and Reader APSB13-22 Multiple Remote Code Execution Vulnerabilities), but has been moved to its own record for better documentation.
Exploit / POC
Adobe Acrobat and Reader CVE-2013-3354 Unspecified Memory Corruption Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Acrobat and Reader CVE-2013-3354 Unspecified Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Adobe Acrobat and Reader CVE-2013-3354 Unspecified Memory Corruption Vulnerability
References:
References:
- Acrobat Homepage (Adobe)
- Adobe Homepage (Adobe)
- Adobe Reader Homepage (Adobe)
- APSB13-22: Security updates available for Adobe Reader and Acrobat (Adobe)