| Vulnerability Name: | CVE-2009-1493 (CCN-50146) | ||||||||||||||||
| Assigned: | 2009-04-27 | ||||||||||||||||
| Published: | 2009-04-27 | ||||||||||||||||
| Updated: | 2017-09-29 | ||||||||||||||||
| Summary: | The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument. | ||||||||||||||||
| CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
7.3 High (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
5.3 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
| ||||||||||||||||
| Vulnerability Type: | CWE-399 | ||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||
| References: | Source: MISC Type: Vendor Advisory http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html Source: CONFIRM Type: UNKNOWN http://blogs.adobe.com/psirt/2009/05/adobe_reader_issue_update.html Source: MITRE Type: CNA CVE-2009-1493 Source: SUSE Type: UNKNOWN SUSE-SA:2009:027 Source: SUSE Type: UNKNOWN SUSE-SR:2009:011 Source: OSVDB Type: UNKNOWN 54129 Source: MISC Type: Exploit http://packetstorm.linuxsecurity.com/0904-exploits/spell.txt Source: CCN Type: Packet Storm Web Site Adobe Reader javascript this.spell.customDictionaryOpen exploit Source: CCN Type: RHSA-2009-0478 Critical: acroread security update Source: CCN Type: SA34924 Adobe Reader JavaScript Methods Memory Corruption Source: SECUNIA Type: Vendor Advisory 34924 Source: SECUNIA Type: UNKNOWN 35055 Source: CCN Type: SA35096 Sun Solaris Adobe Reader Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 35096 Source: SECUNIA Type: UNKNOWN 35152 Source: CCN Type: SA35358 Nortel Media Processing Server Adobe Reader Vulnerabilities Source: SECUNIA Type: UNKNOWN 35358 Source: SECUNIA Type: UNKNOWN 35416 Source: SECUNIA Type: UNKNOWN 35734 Source: GENTOO Type: UNKNOWN GLSA-200907-06 Source: CCN Type: SECTRACK ID: 1022139 Adobe Reader Bugs in getAnnots() and spell.customDictionaryOpen() Let Remote Users Execute Arbitrary Code Source: CCN Type: Sun Alert ID: 259028 Multiple Security Vulnerabilities in Adobe Reader for Solaris 10 May Allow Execution of Arbitrary Code or Cause Denial of Service (DoS) Source: SUNALERT Type: UNKNOWN 259028 Source: CCN Type: ASA-2009-179 acroread security update (RHSA-2009-0478) Source: CCN Type: NORTEL BULLETIN ID: 2009009540, Rev 1 Nortel Response to Adobe APSB09-06 - Security Updates for Adobe Reader and Acrobat Source: CONFIRM Type: UNKNOWN http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=926953 Source: CCN Type: Adobe Web site Adobe Source: CCN Type: Adobe Product Security Advisory APSA09-02 Buffer overflow issues in Adobe Reader and Acrobat Source: CCN Type: Adobe Product Security Bulletin APSB09-06 Security Updates available for Adobe Reader and Acrobat Source: CONFIRM Type: UNKNOWN http://www.adobe.com/support/security/bulletins/apsb09-06.html Source: CCN Type: GLSA-200907-06 Adobe Reader: User-assisted execution of arbitrary code Source: CCN Type: US-CERT VU#970180 Adobe Reader and Acrobat customDictionaryOpen() and getAnnots() JavaScript vulnerabilities Source: CERT-VN Type: US Government Resource VU#970180 Source: CCN Type: OSVDB ID: 54129 Adobe Reader customDictionaryOpen() JavaScript Method PDF Handling Memory Corruption Source: REDHAT Type: UNKNOWN RHSA-2009:0478 Source: BID Type: Exploit 34740 Source: CCN Type: BID-34740 Adobe Reader 'spell.customDictionaryOpen()' JavaScript Function Remote Code Execution Vulnerability Source: SECTRACK Type: UNKNOWN 1022139 Source: CERT Type: US Government Resource TA09-133B Source: VUPEN Type: Vendor Advisory ADV-2009-1189 Source: VUPEN Type: UNKNOWN ADV-2009-1317 Source: XF Type: UNKNOWN reader-spellcustom-code-execution(50146) Source: XF Type: UNKNOWN reader-spellcustom-code-execution(50146) Source: EXPLOIT-DB Type: UNKNOWN 8570 Source: SUSE Type: SUSE-SA:2009:027 Acrobat Reader remote code execution Source: SUSE Type: SUSE-SR:2009:011 SUSE Security Summary Report | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||