XML entity expansion in Adobe Acrobat and Adobe Reader - CVE-2009-2979

 

XML entity expansion in Adobe Acrobat and Adobe Reader - CVE-2009-2979

Published: December 21, 2016 / Updated: January 9, 2017


Vulnerability identifier: #VU2013
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2009-2979
CWE-ID: CWE-776
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Adobe
Affected software:
Adobe Acrobat
Adobe Reader

Detailed vulnerability description

The vulnerability allows a remote attacker to cause DoS conditions on the target system.

The weakness exists due to XMP-XML entity expansion. A remote attacker can create a specially crafted file, trick the victim into opening it and trigger the application to crash.

Successful exploitation of the vulnerability results in denial of service on the vulnerable system.

How to mitigate CVE-2009-2979


Sources