Vulnerability Note VU#422807
Adobe Reader and Acrobat memory corruption vulnerabilities
Overview
Adobe Reader and Acrobat 11.0.01 and earlier, 10.1.5 and earlier, and 9.5.3 and earlier contain memory corruption vulnerabilities.
Description
The Adobe security bulletin APSB13-07 states: Adobe has released security updates for Adobe Reader and Acrobat XI (11.0.01 and earlier) for Windows and Macintosh, X (10.1.5 and earlier) for Windows and Macintosh, 9.5.3 and earlier 9.x versions for Windows and Macintosh, and Adobe Reader 9.5.3 and earlier 9.x versions for Linux. These updates address vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system. Additional details may be found in the full bulletin APSB13-07. |
Impact
A remote attacker may be able to cause a denial of service or execute arbitrary code on the system in the context of the user running the Adobe product. |
Solution
Apply an Update
Users on Windows and Macintosh can utilize the product's update mechanism. The default configuration is set to run automatic update checks on a regular schedule. Update checks can be manually activated by choosing Help > Check for Updates. Adobe Reader users on Windows can also find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows Adobe Reader users on Macintosh can also find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Macintosh Adobe Reader users on Linux can find the appropriate update here: ftp://ftp.adobe.com/pub/adobe/reader/unix/9.x/ Adobe Acrobat Users can utilize the product's update mechanism. The default configuration is set to run automatic update checks on a regular schedule. Update checks can be manually activated by choosing Help > Check for Updates. Acrobat Standard, Pro and Pro Extended users on Windows can also find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows Acrobat Pro users on Macintosh can also find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Macintosh Please consider the following workarounds, if you are unable to apply the update. |
Enable Protected View |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Adobe | Affected | - | 14 Feb 2013 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| Temporal | 8.8 | E:H/RL:W/RC:C |
| Environmental | 8.8 | CDP:MH/TD:H/CR:H/IR:H/AR:H |
References
- https://www.adobe.com/support/security/bulletins/apsb13-07.html
- https://www.adobe.com/support/security/advisories/apsa13-02.html
- https://www.adobe.com/devnet-docs/acrobatetk/tools/AppSec/protectedview.html
- http://blogs.mcafee.com/mcafee-labs/digging-into-the-sandbox-escape-technique-of-the-recent-pdf-exploit
Credit
This document was written by Jared Allar.
Other Information
- CVE IDs: CVE-2013-0640 CVE-2013-0641
- Date Public: 13 Feb 2013
- Date First Published: 14 Feb 2013
- Date Last Updated: 21 Feb 2013
- Document Revision: 13
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.