Adobe Acrobat and Reader CVE-2013-3356 Unspecified Buffer Overflow Vulnerability
BID:62436
Info
Adobe Acrobat and Reader CVE-2013-3356 Unspecified Buffer Overflow Vulnerability
| Bugtraq ID: | 62436 |
| Class: | Unknown |
| CVE: |
CVE-2013-3356 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2013 12:00AM |
| Updated: | Sep 10 2013 12:00AM |
| Credit: | Mateusz Jurczyk and Gynvael Coldwind of the Google Security Team |
| Vulnerable: |
Adobe Reader (for Windows) 11.0.3 Adobe Reader (for Windows) 11.0.2 Adobe Reader (for Windows) 10.1.7 Adobe Reader (for Windows) 10.1.6 Adobe Reader (for Windows) 10.1.5 Adobe Reader (for Windows) 10.0.1 Adobe Reader (for Macintosh) 11.0.3 Adobe Reader (for Macintosh) 11.0.2 Adobe Reader (for Macintosh) 10.1.7 Adobe Reader (for Macintosh) 10.1.6 Adobe Reader (for Macintosh) 10.1.5 Adobe Reader (for Macintosh) 10.0.1 Adobe Acrobat X (for Windows) 11.0.3 Adobe Acrobat (for Windows) 11.0.3 Adobe Acrobat (for Windows) 11.0.2 Adobe Acrobat (for Windows) 11.0.1 Adobe Acrobat (for Windows) 10.1.7 Adobe Acrobat (for Windows) 10.1.6 Adobe Acrobat (for Windows) 10.1.5 Adobe Acrobat (for Macintosh) 11.0.3 Adobe Acrobat (for Macintosh) 11.0.2 Adobe Acrobat (for Macintosh) 11.0.1 Adobe Acrobat (for Macintosh) 10.1.7 Adobe Acrobat (for Macintosh) 10.1.6 Adobe Acrobat (for Macintosh) 10.1.5 |
| Not Vulnerable: |
Adobe Reader XI (for Macintosh) 11.0.4 Adobe Reader X (for Windows) 10.1.8 Adobe Reader X (for Macintosh) 10.1.8 Adobe Reader (for Windows) 11.0.4 Adobe Acrobat XI (for Macintosh) 11.0.4 Adobe Acrobat X (for Windows) 10.1.8 Adobe Acrobat X (for Macintosh) 10.1.8 Adobe Acrobat (for Windows) 11.0.4 |
Discussion
Adobe Acrobat and Reader CVE-2013-3356 Unspecified Buffer Overflow Vulnerability
Adobe Acrobat and Reader are prone to an unspecified buffer-overflow vulnerability.
Limited information is currently available regarding this issue. We will update this BID as more information emerges.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Failed attacks may cause a denial-of-service condition.
Note: This issue was previously discussed in BID 62293 (Adobe Acrobat and Reader APSB13-22 Multiple Remote Code Execution Vulnerabilities), but has been moved to its own record for better documentation.
Adobe Acrobat and Reader are prone to an unspecified buffer-overflow vulnerability.
Limited information is currently available regarding this issue. We will update this BID as more information emerges.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Failed attacks may cause a denial-of-service condition.
Note: This issue was previously discussed in BID 62293 (Adobe Acrobat and Reader APSB13-22 Multiple Remote Code Execution Vulnerabilities), but has been moved to its own record for better documentation.
Exploit / POC
Adobe Acrobat and Reader CVE-2013-3356 Unspecified Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Acrobat and Reader CVE-2013-3356 Unspecified Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Adobe Acrobat and Reader CVE-2013-3356 Unspecified Buffer Overflow Vulnerability
References:
References:
- Acrobat Homepage (Adobe)
- Adobe Homepage (Adobe)
- Adobe Reader Homepage (Adobe)
- APSB13-22: Security updates available for Adobe Reader and Acrobat (Adobe)