CVE-2009-0658
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 87.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 87.83% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- adobe/acrobat · adobe/acrobat reader
- Source
- cve@mitre.org
References
- http://isc.sans.org/diary.html?n&storyid=5902Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.htmlThird Party Advisory
- http://osvdb.org/52073Broken Link
- http://secunia.com/advisories/33901Third Party Advisory
- http://secunia.com/advisories/34392Third Party Advisory
- http://secunia.com/advisories/34490Third Party Advisory
- http://secunia.com/advisories/34706Third Party Advisory
- http://secunia.com/advisories/34790Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200904-17.xmlThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-256788-1Third Party Advisory
- http://www.adobe.com/support/security/advisories/apsa09-01.htmlVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb09-04.htmlVendor Advisory
- http://www.kb.cert.org/vuls/id/905281Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2009-0376.htmlThird Party Advisory
- http://www.securityfocus.com/bid/33751Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1021739Third Party Advisory, VDB Entry
- http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090219Third Party Advisory
- http://www.symantec.com/security_response/writeup.jsp?docid=2009-021212-5523-99&tabid=2Third Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA09-051A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2009/0472Third Party Advisory
- http://www.vupen.com/english/advisories/2009/1019Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48825VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5697Tool Signature
- https://www.exploit-db.com/exploits/8090Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/8099Third Party Advisory, VDB Entry
- http://isc.sans.org/diary.html?n&storyid=5902Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.htmlThird Party Advisory
- http://osvdb.org/52073Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.