XML entity expansion in Adobe Acrobat and Adobe Reader - CVE-2009-2979

 

XML entity expansion in Adobe Acrobat and Adobe Reader - CVE-2009-2979

Published: December 21, 2016 / Updated: January 9, 2017


Vulnerability identifier: #VU2013
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2009-2979
CWE-ID: CWE-776
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS conditions on the target system.

The weakness exists due to XMP-XML entity expansion. A remote attacker can create a specially crafted file, trick the victim into opening it and trigger the application to crash.

Successful exploitation of the vulnerability results in denial of service on the vulnerable system.

Affected software

Adobe Acrobat
Adobe Reader
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop

How to mitigate CVE-2009-2979



External References

Related Security Bulletins