Security bypass in Adobe Acrobat and Adobe Reader - CVE-2008-0667

 

Security bypass in Adobe Acrobat and Adobe Reader - CVE-2008-0667

Published: December 15, 2016 / Updated: March 7, 2017


Vulnerability identifier: #VU1331
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2008-0667
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists due to an error in JavaScript API DOC.print function. By sending a malicious PDF file and persuading a victim to open it, a remote attacker can configure silent non-interactive printing of an arbitrary number of copies of .pdf files.

Successful exploitation of the vulnerability results in unauthorized access to the vulnerable system.

Affected software

Adobe Acrobat
Adobe Reader
SUSE Linux

How to mitigate CVE-2008-0667



External References

Related Security Bulletins