Adobe Reader CVE-2014-0511 Heap Based Buffer Overflow Vulnerability
BID:66205
Info
Adobe Reader CVE-2014-0511 Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 66205 |
| Class: | Unknown |
| CVE: |
CVE-2014-0511 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 13 2014 12:00AM |
| Updated: | May 29 2014 12:55AM |
| Credit: | VUPEN Security (Pwn2Own 2014), working with HP's Zero Day Initiative |
| Vulnerable: |
Adobe Reader 10.1.3 Adobe Reader 10.1.2 Adobe Reader 10.1.1 Adobe Reader 10.1 Adobe Reader 10.0.3 Adobe Reader 10.0.2 Adobe Reader 10.0.1 Adobe Reader 10.0 Adobe Acrobat 10.1.3 Adobe Acrobat 10.1.2 Adobe Acrobat 10.1.1 Adobe Acrobat 10.1 Adobe Acrobat 10.0.3 Adobe Acrobat 10.0.2 Adobe Acrobat 10.0.1 Adobe Acrobat 10.0 |
| Not Vulnerable: | |
Discussion
Adobe Reader CVE-2014-0511 Heap Based Buffer Overflow Vulnerability
Adobe Reader is prone to a heap-based buffer-overflow vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts likely result in denial-of-service conditions.
Adobe Reader 11.0.6 is vulnerable; other versions may also be affected.
Adobe Reader is prone to a heap-based buffer-overflow vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts likely result in denial-of-service conditions.
Adobe Reader 11.0.6 is vulnerable; other versions may also be affected.
Exploit / POC
Adobe Reader CVE-2014-0511 Heap Based Buffer Overflow Vulnerability
Exploitation of this issue was demonstrated at the Pwn2Own contest, but the exploit is not publicly available.
Exploitation of this issue was demonstrated at the Pwn2Own contest, but the exploit is not publicly available.
Solution / Fix
Adobe Reader CVE-2014-0511 Heap Based Buffer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Adobe Reader CVE-2014-0511 Heap Based Buffer Overflow Vulnerability
References:
References:
- Adobe Homepage (Adobe)