Description: | Summary: Adobe Acrobat Reader DC (Classic Track) is prone to multiple vulnerabilities.
Vulnerability Insight: Multiple flaws exist due to:
- Two access of uninitialized point vulnerabilities that could result in remote could execution,
- Six use after free vulnerabilities that could result in remote code execution.
- Five buffer access with incorrect length value vulnerabilities that could result in remote code execution.
- Six buffer over-read vulnerabilities that could result in remote code execution.
- A buffer overflow vulnerability that could result in remote code execution.
- A heap overflow vulnerability that could result in remote code execution.
- Two improper validation of array index vulnerabilities that could result in remote code execution.
- Multiple out-of-bounds read vulnerabilities that could result in remote code execution.
- Four out-of-bounds write vulnerabilities that could result in remote code execution.
- Two security bypass vulnerabilities that could result in drive-by-downloads.
- A security bypass vulnerability that could result in information disclosure.
- A security bypass vulnerability that could result in remote code execution.
- A stack exhaustion vulnerability that could result in excessive resource consumption.
- Three type confusion vulnerabilities that could result in remote code execution.
- Six untrusted pointer dereference vulnerabilities that could result in remote code execution.
Please see the references for more information on the vulnerabilities.
Vulnerability Impact: Successful exploitation will allow remote attackers to execute arbitrary code in the context of the application. Failed attacks may cause a denial-of-service condition. Also attackers will be able to gain access to potentially sensitive information, get excessive resource consumption and get unintentional download of malicious software.
Affected Software/OS: Adobe Acrobat Reader DC (Classic Track) 2015.006.30355 and earlier versions on Mac OS X.
Solution: Upgrade to Adobe Acrobat DC (Classic Track) version 2015.006.30392 or later.
CVSS Score: 10.0
CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
|