Vulnerability Name:

CVE-2009-1493 (CCN-50146)

Assigned:2009-04-27
Published:2009-04-27
Updated:2017-09-29
Summary:The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
7.3 High (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.3 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-399
Vulnerability Consequences:Gain Access
References:Source: MISC
Type: Vendor Advisory
http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html

Source: CONFIRM
Type: UNKNOWN
http://blogs.adobe.com/psirt/2009/05/adobe_reader_issue_update.html

Source: MITRE
Type: CNA
CVE-2009-1493

Source: SUSE
Type: UNKNOWN
SUSE-SA:2009:027

Source: SUSE
Type: UNKNOWN
SUSE-SR:2009:011

Source: OSVDB
Type: UNKNOWN
54129

Source: MISC
Type: Exploit
http://packetstorm.linuxsecurity.com/0904-exploits/spell.txt

Source: CCN
Type: Packet Storm Web Site
Adobe Reader javascript this.spell.customDictionaryOpen exploit

Source: CCN
Type: RHSA-2009-0478
Critical: acroread security update

Source: CCN
Type: SA34924
Adobe Reader JavaScript Methods Memory Corruption

Source: SECUNIA
Type: Vendor Advisory
34924

Source: SECUNIA
Type: UNKNOWN
35055

Source: CCN
Type: SA35096
Sun Solaris Adobe Reader Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
35096

Source: SECUNIA
Type: UNKNOWN
35152

Source: CCN
Type: SA35358
Nortel Media Processing Server Adobe Reader Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
35358

Source: SECUNIA
Type: UNKNOWN
35416

Source: SECUNIA
Type: UNKNOWN
35734

Source: GENTOO
Type: UNKNOWN
GLSA-200907-06

Source: CCN
Type: SECTRACK ID: 1022139
Adobe Reader Bugs in getAnnots() and spell.customDictionaryOpen() Let Remote Users Execute Arbitrary Code

Source: CCN
Type: Sun Alert ID: 259028
Multiple Security Vulnerabilities in Adobe Reader for Solaris 10 May Allow Execution of Arbitrary Code or Cause Denial of Service (DoS)

Source: SUNALERT
Type: UNKNOWN
259028

Source: CCN
Type: ASA-2009-179
acroread security update (RHSA-2009-0478)

Source: CCN
Type: NORTEL BULLETIN ID: 2009009540, Rev 1
Nortel Response to Adobe APSB09-06 - Security Updates for Adobe Reader and Acrobat

Source: CONFIRM
Type: UNKNOWN
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=926953

Source: CCN
Type: Adobe Web site
Adobe

Source: CCN
Type: Adobe Product Security Advisory APSA09-02
Buffer overflow issues in Adobe Reader and Acrobat

Source: CCN
Type: Adobe Product Security Bulletin APSB09-06
Security Updates available for Adobe Reader and Acrobat

Source: CONFIRM
Type: UNKNOWN
http://www.adobe.com/support/security/bulletins/apsb09-06.html

Source: CCN
Type: GLSA-200907-06
Adobe Reader: User-assisted execution of arbitrary code

Source: CCN
Type: US-CERT VU#970180
Adobe Reader and Acrobat customDictionaryOpen() and getAnnots() JavaScript vulnerabilities

Source: CERT-VN
Type: US Government Resource
VU#970180

Source: CCN
Type: OSVDB ID: 54129
Adobe Reader customDictionaryOpen() JavaScript Method PDF Handling Memory Corruption

Source: REDHAT
Type: UNKNOWN
RHSA-2009:0478

Source: BID
Type: Exploit
34740

Source: CCN
Type: BID-34740
Adobe Reader 'spell.customDictionaryOpen()' JavaScript Function Remote Code Execution Vulnerability

Source: SECTRACK
Type: UNKNOWN
1022139

Source: CERT
Type: US Government Resource
TA09-133B

Source: VUPEN
Type: Vendor Advisory
ADV-2009-1189

Source: VUPEN
Type: UNKNOWN
ADV-2009-1317

Source: XF
Type: UNKNOWN
reader-spellcustom-code-execution(50146)

Source: XF
Type: UNKNOWN
reader-spellcustom-code-execution(50146)

Source: EXPLOIT-DB
Type: UNKNOWN
8570

Source: SUSE
Type: SUSE-SA:2009:027
Acrobat Reader remote code execution

Source: SUSE
Type: SUSE-SR:2009:011
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:adobe:reader:8.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:reader:9.1:*:*:*:*:*:*:*
  • AND
  • cpe:/o:linux:linux_kernel:*:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:rhel_extras:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:rhel_extras:5:*:*:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/a:redhat:rhel_extras:3:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:adobe:reader:8.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:reader:9.1:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::sparc:*:*:*:*:*
  • OR cpe:/a:redhat:rhel_extras:3:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:rhel_extras:4:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:10.3:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:11.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20091493
    V
    CVE-2009-1493
    2015-11-16
    oval:org.mitre.oval:def:22282
    P
    ELSA-2009:0478: acroread security update (Critical)
    2014-05-26
    oval:com.redhat.rhsa:def:20090478
    P
    RHSA-2009:0478: acroread security update (Critical)
    2009-05-13
    BACK
    adobe reader 8.1.4
    adobe reader 9.1
    linux linux *
    adobe reader 8.1.4
    adobe reader 9.1
    gentoo linux *
    sun solaris 10
    redhat rhel extras 3
    redhat rhel extras 4
    novell opensuse 10.3
    novell opensuse 11.0