CVE-2006-5857
published 2006-12-31CVE-2006-5857: Adobe Reader and Acrobat 7.0.8 and earlier allows user-assisted remote attackers to execute code via a crafted PDF file that triggers memory corruption and…
PriorityP337critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
9.09%
94.8th percentile
Adobe Reader and Acrobat 7.0.8 and earlier allows user-assisted remote attackers to execute code via a crafted PDF file that triggers memory corruption and overwrites a subroutine pointer during rendering.
Affected
54 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | <= 7.0.8 | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7gvq-qwwx-xxf5: Adobe Reader and Acrobat 7
ghsa_unreviewed·2022-05-01
CVE-2006-5857 [HIGH] GHSA-7gvq-qwwx-xxf5: Adobe Reader and Acrobat 7
Adobe Reader and Acrobat 7.0.8 and earlier allows user-assisted remote attackers to execute code via a crafted PDF file that triggers memory corruption and overwrites a subroutine pointer during rendering.
Red Hat
security flaw
vendor_redhat·2007-01-10·CVSS 9.3
CVE-2006-5857 [CRITICAL] security flaw
security flaw
Adobe Reader and Acrobat 7.0.8 and earlier allows user-assisted remote attackers to execute code via a crafted PDF file that triggers memory corruption and overwrites a subroutine pointer during rendering.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-5857 security flaw
bugzilla·2018-08-16·CVSS 9.3
CVE-2006-5857 [CRITICAL] CVE-2006-5857 security flaw
CVE-2006-5857 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Adobe Reader and Acrobat 7.0.8 and earlier allows user-assisted remote attackers to execute code via a crafted PDF file that triggers memory corruption and overwrites a subroutine pointer during rendering.
Bugzilla
CVE-2006-5857 Multiple Acrobat vulnerabilities (CVE-2007-0045 CVE-2007-0046)
bugzilla·2007-01-11·CVSS 9.3
CVE-2006-5857 [CRITICAL] CVE-2006-5857 Multiple Acrobat vulnerabilities (CVE-2007-0045 CVE-2007-0046)
CVE-2006-5857 Multiple Acrobat vulnerabilities (CVE-2007-0045 CVE-2007-0046)
Adobe informed us of several security vulnerabilities in Adobe Reader 7.0.8 and
earlier. They are releasing Adobe Reader 7.0.9 which fixes these flaws.
Discussion:
Please note that at this time we do not have an update for Adobe Acrobat Reader
on Red Hat Enterprise Linux 3. This is because the binaries supplied by Adobe
now rely on newer versions of libraries than were shipped with Red Hat
Enterprise Linux 3. We are currently working through possible solutions to this
problem.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
Bugzilla
CVE-2006-5857 Multiple Acrobat vulnerabilities (CVE-2007-0045 CVE-2007-0046)
bugzilla·2007-01-05·CVSS 9.3
CVE-2006-5857 [CRITICAL] CVE-2006-5857 Multiple Acrobat vulnerabilities (CVE-2007-0045 CVE-2007-0046)
CVE-2006-5857 Multiple Acrobat vulnerabilities (CVE-2007-0045 CVE-2007-0046)
Adobe informed us of several security vulnerabilities in Adobe Reader 7.0.8 and
earlier. They are releasing Adobe Reader 7.0.9 which fixes these flaws.
Discussion:
These flaws also affect the Adobe Reader shipped with RHEL3.
---
Lifting embargo:
http://www.adobe.com/support/security/bulletins/apsb07-01.html
---
Please note that at this time we do not have an update for Adobe Acrobat Reader
on Red Hat Enterprise Linux 3. This is because the binaries supplied by Adobe
now rely on newer versions of libraries than were shipped with Red Hat
Enterprise Linux 3. We are currently working through possible solutions to this
problem.
---
An advisory has been issued which should help the problem
described in this bug
http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0200.htmlhttp://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.htmlhttp://osvdb.org/31316http://secunia.com/advisories/23666http://secunia.com/advisories/23691http://secunia.com/advisories/23812http://secunia.com/advisories/23877http://secunia.com/advisories/23882http://secunia.com/advisories/24533http://security.gentoo.org/glsa/glsa-200701-16.xmlhttp://securitytracker.com/id?1017491http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1http://www.adobe.com/support/security/bulletins/apsb07-01.htmlhttp://www.kb.cert.org/vuls/id/698924http://www.piotrbania.com/all/adv/adobe-acrobat-adv.txthttp://www.redhat.com/support/errata/RHSA-2007-0021.htmlhttp://www.securityfocus.com/archive/1/456491/100/0/threadedhttp://www.securityfocus.com/bid/21981http://www.vupen.com/english/advisories/2007/0115http://www.vupen.com/english/advisories/2007/0957https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11698https://rhn.redhat.com/errata/RHSA-2007-0017.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2007-01/0200.htmlhttp://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.htmlhttp://osvdb.org/31316http://secunia.com/advisories/23666http://secunia.com/advisories/23691http://secunia.com/advisories/23812http://secunia.com/advisories/23877http://secunia.com/advisories/23882http://secunia.com/advisories/24533http://security.gentoo.org/glsa/glsa-200701-16.xmlhttp://securitytracker.com/id?1017491http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1http://www.adobe.com/support/security/bulletins/apsb07-01.htmlhttp://www.kb.cert.org/vuls/id/698924http://www.piotrbania.com/all/adv/adobe-acrobat-adv.txthttp://www.redhat.com/support/errata/RHSA-2007-0021.htmlhttp://www.securityfocus.com/archive/1/456491/100/0/threadedhttp://www.securityfocus.com/bid/21981http://www.vupen.com/english/advisories/2007/0115http://www.vupen.com/english/advisories/2007/0957https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11698https://rhn.redhat.com/errata/RHSA-2007-0017.html
2006-12-31
Published