Vulnerability Name:

CVE-2005-0492 (CCN-19946)

Assigned:2005-04-01
Published:2005-04-01
Updated:2017-07-11
Summary:Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page node.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-20
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2005-0492

Source: BUGTRAQ
Type: Third Party Advisory
20050218 Adobe Reader invalid root page node Count value DOS

Source: CCN
Type: BugTraq Mailing List, 2005-02-18 1:33:22
Adobe Reader invalid root page node Count value DOS

Source: CCN
Type: SA14813
Adobe Reader / Adobe Acrobat Local Files Detection and Denial of Service

Source: SECUNIA
Type: Broken Link, Not Applicable
14813

Source: CCN
Type: Adobe Download Web page
downloads

Source: CCN
Type: Adobe Support Knowledgebase Document 331468
Adobe Reader and Adobe Acrobat invalid root page node Count.

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.adobe.com/support/techdocs/331468.html

Source: CCN
Type: OSVDB ID: 14819
Adobe Acrobat/Reader Malformed PDF Negative Count Value DoS

Source: VUPEN
Type: Permissions Required
ADV-2005-0310

Source: XF
Type: UNKNOWN
adobe-root-page-node-dos(19946)

Source: XF
Type: UNKNOWN
adobe-root-page-node-dos(19946)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:adobe:acrobat_reader:6.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:7.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:adobe:acrobat_reader:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:6.0.3:*:*:*:*:*:*:*
  • AND
  • cpe:/o:apple:mac_os_x:10.2.8:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.3:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    adobe acrobat reader 6.0.3
    adobe acrobat reader 7.0
    adobe acrobat reader 7.0
    adobe acrobat reader 6.0.3
    apple mac os x 10.2.8
    apple mac os x 10.3
    apple mac os x 10.2