CVE-2008-0667
The DOC.print function in the Adobe JavaScript API, as used by Adobe Acrobat and Reader before 8.1.2, allows remote attackers to configure silent non-interactive printing, and trigger the printing of an arbitrary number of copies of a document.
Does this matter?
Lower severity and a low EPSS score (6.91%). Track it; it rarely justifies an emergency change on its own.
Description
The DOC.print function in the Adobe JavaScript API, as used by Adobe Acrobat and Reader before 8.1.2, allows remote attackers to configure silent non-interactive printing, and trigger the printing of an arbitrary number of copies of a document. NOTE: this issue might be subsumed by CVE-2008-0655.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 6.91% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- adobe/acrobat reader
- Source
- cve@mitre.org
References
- http://kb.adobe.com/selfservice/viewContent.do?externalId=kb403079&sliceId=1
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00007.html
- http://secunia.com/advisories/28802Patch, Vendor Advisory
- http://secunia.com/advisories/28851Patch, Vendor Advisory
- http://secunia.com/advisories/28983Vendor Advisory
- http://secunia.com/advisories/29065Vendor Advisory
- http://secunia.com/advisories/29205
- http://secunia.com/advisories/30840
- http://security.gentoo.org/glsa/glsa-200803-01.xml
- http://securityreason.com/securityalert/3625
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-239286-1
- http://www.adobe.com/support/security/advisories/apsa08-01.htmlPatch
- http://www.adobe.com/support/security/bulletins/apsb08-13.html
- http://www.fortiguardcenter.com/advisory/FGA-2008-04.html
- http://www.redhat.com/support/errata/RHSA-2008-0144.html
- http://www.securityfocus.com/archive/1/487760/100/0/threaded
- http://www.securityfocus.com/bid/27641Patch
- http://www.us-cert.gov/cas/techalerts/TA08-043A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2008/0425/references
- http://www.vupen.com/english/advisories/2008/1966/references
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9731
- http://kb.adobe.com/selfservice/viewContent.do?externalId=kb403079&sliceId=1
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00007.html
- http://secunia.com/advisories/28802Patch, Vendor Advisory
- http://secunia.com/advisories/28851Patch, Vendor Advisory
- http://secunia.com/advisories/28983Vendor Advisory
- http://secunia.com/advisories/29065Vendor Advisory
- http://secunia.com/advisories/29205
- http://secunia.com/advisories/30840
- http://security.gentoo.org/glsa/glsa-200803-01.xml
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.