Vulnerability Name:

CVE-2005-2470 (CCN-21860)

Assigned:2005-08-16
Published:2005-08-16
Updated:2017-07-11
Summary:Buffer overflow in a "core application plug-in" for Adobe Reader 5.1 through 7.0.2 and Acrobat 5.0 through 7.0.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2005-2470

Source: CCN
Type: RHSA-2005-750
Adobe Acrobat Reader security update

Source: CCN
Type: SA16466
Adobe Acrobat / Reader Plug-in Buffer Overflow Vulnerability

Source: SECUNIA
Type: UNKNOWN
16466

Source: CCN
Type: SECTRACK ID: 1014712
Adobe Acrobat and Adobe Reader Buffer Overflow in Core Plug-in Lets Remote Users Execute Arbitrary Code

Source: SECTRACK
Type: UNKNOWN
1014712

Source: CCN
Type: Adobe Acrobat Web page
Adobe Acrobat family

Source: CCN
Type: Acrobat Reader Web site
Acrobat Reader

Source: CCN
Type: Adobe Systems Incorporated Downloads Web page
Downloads

Source: CCN
Type: Adobe Support Knowledgebase Document 321644
Security Advisory: Acrobat and Adobe Reader plug-in buffer overflow

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.adobe.com/support/techdocs/321644.html

Source: CCN
Type: CIAC Information Bulletin P-275
Adobe Acrobat and Reader Plug-in Buffer Overflow

Source: CCN
Type: GLSA-200508-11
Adobe Reader: Buffer Overflow

Source: GENTOO
Type: UNKNOWN
GLSA-200508-11

Source: CCN
Type: US-CERT VU#896220
Adobe Acrobat contains a remotely exploitable buffer overflow

Source: CERT-VN
Type: US Government Resource
VU#896220

Source: SUSE
Type: UNKNOWN
SUSE-SR:2005:019

Source: REDHAT
Type: UNKNOWN
RHSA-2005:750

Source: BID
Type: UNKNOWN
14603

Source: CCN
Type: BID-14603
Adobe Acrobat and Adobe Reader Remote Buffer Overflow Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2005-1434

Source: XF
Type: UNKNOWN
adobe-acrobat-reader-plugin-bo(21860)

Source: XF
Type: UNKNOWN
adobe-acrobat-reader-plugin-bo(21860)

Source: SUSE
Type: SUSE-SA:2005:047
acroread: remote code execution

Source: SUSE
Type: SUSE-SR:2005:019
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:adobe:acrobat:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:5.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:6.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:6.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:7.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:7.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:5.1:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:6.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:6.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:6.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:7.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:7.0.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:adobe:acrobat_reader:6.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:6.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:7.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:7.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:7.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:5.1:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:6.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:5.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:6.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:6.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:7.0.2:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_server:8:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:9.1:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:9.2:*:*:*:*:*:*:*
  • OR cpe:/o:novell:linux_desktop:9:*:*:*:*:*:*:*
  • OR cpe:/a:suse:suse_open_enterprise_server:9:*:*:*:*:*:*:*
  • OR cpe:/a:novell:open_enterprise_server:*:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:rhel_extras:3:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:rhel_extras:4:*:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*
  • OR cpe:/a:novell:open_enterprise_server:*:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:9.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:29418
    V
    Buffer overflow in a "core application plug-in" for Adobe Reader 5.1 through 7.0.2 and Acrobat 5.0 through 7.0.2 (CVE-2005-2470)
    2015-12-22
    oval:org.opensuse.security:def:20052470
    V
    CVE-2005-2470
    2015-11-16
    BACK
    adobe acrobat 5.0
    adobe acrobat 5.0.5
    adobe acrobat 6.0
    adobe acrobat 6.0.1
    adobe acrobat 6.0.2
    adobe acrobat 7.0
    adobe acrobat 7.0.1
    adobe acrobat 7.0.2
    adobe acrobat reader 5.1
    adobe acrobat reader 6.0
    adobe acrobat reader 6.0.1
    adobe acrobat reader 6.0.2
    adobe acrobat reader 6.0.3
    adobe acrobat reader 7.0
    adobe acrobat reader 7.0.1
    adobe acrobat reader 7.0.2
    adobe acrobat reader 6.0.1
    adobe acrobat reader 6.0
    adobe acrobat reader 6.0.2
    adobe acrobat reader 7.0
    adobe acrobat reader 7.0.1
    adobe acrobat 7.0
    adobe acrobat 7.0.1
    adobe acrobat reader 7.0.2
    adobe acrobat reader 5.1
    adobe acrobat reader 6.0.3
    adobe acrobat 5.0
    adobe acrobat 5.0.5
    adobe acrobat 6.0
    adobe acrobat 6.0.1
    adobe acrobat 6.0.2
    adobe acrobat 7.0.2
    gentoo linux *
    suse linux enterprise server 8
    suse suse linux 9.0
    suse suse linux 9.1
    suse suse linux 9.2
    novell linux desktop 9
    suse suse open enterprise server 9
    novell open enterprise server *
    redhat rhel extras 3
    redhat rhel extras 4
    suse linux enterprise server 9
    novell open enterprise server *
    suse suse linux 9.3