Cross-site scripting in Adobe Acrobat and Adobe Reader - CVE-2007-0048
Published: December 21, 2016
Adobe Acrobat
Adobe Reader
Detailed vulnerability description
The vulnerability exists due to incorrect filtration of input data. A remote attacker can append specially URL containing a long sequence of # (hash) characters to PDF file, trick the victim into opening it, trigger memory corruption and cause the affected browser to crash.
Successful exploitation of this vulnerability results in denial of service on the vulnerable system.
How to mitigate CVE-2007-0048
http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Macintosh
http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Unix
Update Adobe Acrobat for Windows and Macintosh to version 9.2:
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=158&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=112&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Macintosh