VulDB: Adobe Acrobat/Reader 9.5.1/10.1.3 buffer overflow [CVE-2012-4159]
General

scipID: 5971
Affected: Adobe Acrobat/Reader 9.5.1/10.1.3
Published: 08/14/2012 (Mateusz Jurczyk/Gynvael Coldwind)
Risk:
critical
Entry: 92% complete
Created: 08/17/2012
Updated: 09/03/2012
Summary
A vulnerability classified as critical was found in Adobe Acrobat and Reader 9.5.1/10.1.3. Affected by this vulnerability is an unknown function. The manipulation with an unknown input leads to a buffer overflow vulnerability. As an impact it is known to affect confidentiality, integrity, and availability.
The weakness was released 08/14/2012 by Mateusz Jurczyk and Gynvael Coldwind with Google Security Team as APSB12-16 as bulletin (Website). The advisory is shared for download at adobe.com. The public release was coordinated with Adobe. This vulnerability is known as CVE-2012-4159 since 08/07/2012. The exploitability is known to be difficult. The attack can only be done within the local network. The exploitation doesn’t need any form of authentication. Technical details are unknown but a private exploit is available.
Upgrading to version 9.5.2 or 10.1.4 eliminates this vulnerability. The upgrade is hosted for download at get.adobe.com. A possible mitigation has been published immediately after the disclosure of the vulnerability. The vulnerability is also documented in the databases at OSVDB (84631) and Secunia (SA50281).CVSS
Base Score: 6.8 (CVSS2#AV:A/AC:H/Au:N/C:C/I:C/A:C) [?]
| Access Vector | Access Complexity | Authentication | Confidentiality | Integrity | Availability |
|---|---|---|---|---|---|
| Local | High | Multiple | None | None | None |
| Adjacent | Medium | Single | Partial | Partial | Partial |
| Network | Low | None | Complete | Complete | Complete |
Exploiting
Class: Buffer overflow
Local: No
Remote: Partially
Availability: Yes
Access: Private
Countermeasures
Recommended: Upgrade
Reaction Time: 0 days since reported
0-Day Time: 0 days since found
Exposure Time: 0 days since known
Upgrade: Acrobat/Reader 9.5.2/10.1.4
Timeline
08/07/2012 | CVE assigned
08/14/2012 | Advisory disclosed
08/14/2012 | Countermeasure disclosed
08/14/2012 | OSVDB entry created
08/17/2012 | VulDB entry created
09/03/2012 | VulDB entry updated
Sources
Advisory: APSB12-16
Researcher: Mateusz Jurczyk/Gynvael Coldwind
Company: Google Security Team
Coordinated: Yes
OSVDB: 84631
CVE: CVE-2012-4159 (mitre.org) (nist.org) (cvedetails.com)
Secunia: 50281
- Latest Entries
- Apple QuickTime DREF Atom Handler buffer overflow [CVE-2013-1017]
- Apple QuickTime H.264 Handler buffer overflow [CVE-2013-1018]
- Apple QuickTime MP3 File Handler buffer overflow [CVE-2013-0989]
- Apple QuickTime Sorenson Codec Handler buffer overflow [CVE-2013-1019]
- Apple QuickTime JPEG Handler buffer overflow [CVE-2013-1020]
- Statistics
- Archive



















