cbcvebase.
CVE-2009-1493
published 2009-04-30

CVE-2009-1493: The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a…

PriorityP265medium6.8CVSS 2.0
AVNACMAuNCPIPAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
21.83%
97.4th percentile
The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.

Affected

2 ranges
VendorProductVersion rangeFixed in
adobereader
adobereader

Detection & IOCsextracted from sources · hover to see the quote

commandthis.spell.customDictionaryOpen(0,nop);
snort
GID 1, SID 15492
bytes
%uc92b%ue983%ud9ee%ud9ee%u2474%u5bf4%u7381%uc513%u4871%u83a5%ufceb%uf4e2%uaaf4%ue61b%u1b96%ucf4a%u29a3%u44c1%uf108%ufcdb%u4e75%u2585%u088c%ufeb1%u199f%ua442%u88da%ucd2e%ucac4%uc30b%uf896%u15a9%u21a3%uf619%u904c%u680b%u2345%u8a20%u02ea%ucd20%u13ea%ucb21%u924c%uf61a%u904c%uaef8%uf108%ua548
  • Exploit triggers via a call to the JavaScript API method customDictionaryOpen() in a PDF document with a long string in the second argument; detect PDF files invoking this method with oversized second parameters.
  • Exploit uses heap spray with NOP sled (%u9090%u9090) repeated to fill ~0x10000/2 bytes, followed by shellcode; detect large repeated Unicode NOP patterns in PDF JavaScript streams.
  • Exploit targets Adobe Reader on Linux/UNIX only; triage PDF files with embedded JavaScript calling spell.customDictionaryOpen() on Linux/UNIX deployments of Adobe Reader 9.1, 8.1.4, 7.1.1 and earlier.
  • ·Adobe recommended disabling JavaScript in Adobe Reader as a mitigation until a patch was available; the vulnerability is only exploitable when JavaScript is enabled.
  • ·The vulnerability affects Adobe Reader on Linux and UNIX platforms only; Windows users are not affected by CVE-2009-1493.

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck6.8MEDIUM
vendor_redhat6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.