Cross-site scripting in Adobe Acrobat and Adobe Reader - CVE-2007-0048

 

Cross-site scripting in Adobe Acrobat and Adobe Reader - CVE-2007-0048

Published: December 21, 2016


Vulnerability identifier: #VU1835
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
CVE-ID: CVE-2007-0048
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Adobe
Affected software:
Adobe Acrobat
Adobe Reader

Detailed vulnerability description

The vulnerability allows a remote attacker to perform cross-site scripting (XSS) attack.

The vulnerability exists due to incorrect filtration of input data. A remote attacker can append specially URL containing a long sequence of # (hash) characters to PDF file, trick the victim into opening it, trigger memory corruption and cause the affected browser to crash.

Successful exploitation of this vulnerability results in denial of service on the vulnerable system.


How to mitigate CVE-2007-0048


Sources