CVE-2009-1493
published 2009-04-30CVE-2009-1493: The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a…
PriorityP265medium6.8CVSS 2.0
AVNACMAuNCPIPAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
21.83%
97.4th percentile
The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | reader | — | — |
| adobe | reader | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
GID 1, SID 15492
bytes↗
%uc92b%ue983%ud9ee%ud9ee%u2474%u5bf4%u7381%uc513%u4871%u83a5%ufceb%uf4e2%uaaf4%ue61b%u1b96%ucf4a%u29a3%u44c1%uf108%ufcdb%u4e75%u2585%u088c%ufeb1%u199f%ua442%u88da%ucd2e%ucac4%uc30b%uf896%u15a9%u21a3%uf619%u904c%u680b%u2345%u8a20%u02ea%ucd20%u13ea%ucb21%u924c%uf61a%u904c%uaef8%uf108%ua548
- →Exploit triggers via a call to the JavaScript API method customDictionaryOpen() in a PDF document with a long string in the second argument; detect PDF files invoking this method with oversized second parameters. ↗
- →Exploit uses heap spray with NOP sled (%u9090%u9090) repeated to fill ~0x10000/2 bytes, followed by shellcode; detect large repeated Unicode NOP patterns in PDF JavaScript streams. ↗
- →Exploit targets Adobe Reader on Linux/UNIX only; triage PDF files with embedded JavaScript calling spell.customDictionaryOpen() on Linux/UNIX deployments of Adobe Reader 9.1, 8.1.4, 7.1.1 and earlier. ↗
- ·Adobe recommended disabling JavaScript in Adobe Reader as a mitigation until a patch was available; the vulnerability is only exploitable when JavaScript is enabled. ↗
- ·The vulnerability affects Adobe Reader on Linux and UNIX platforms only; Windows users are not affected by CVE-2009-1493. ↗
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck6.8MEDIUM
vendor_redhat6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f62c-gjq3-9jwj: The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9
ghsa_unreviewed·2022-05-02
CVE-2009-1493 [MEDIUM] GHSA-f62c-gjq3-9jwj: The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9
The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.
VulnCheck
Adobe Reader customDictionaryOpen Spell Method Vulnerability
vulncheck·2009·CVSS 6.8
CVE-2009-1493 [MEDIUM] Adobe Reader customDictionaryOpen Spell Method Vulnerability
Adobe Reader customDictionaryOpen Spell Method Vulnerability
The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.
Affected: Adobe Acrobat and Reader
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://blog.talosintelligence.com/acrobat-javascript-blacklist-framework/
Red Hat
acroread: multiple vulnerabilities in Adobe Reader 8.1.4
vendor_redhat·2009-04-27·CVSS 6.8
CVE-2009-1493 [MEDIUM] acroread: multiple vulnerabilities in Adobe Reader 8.1.4
acroread: multiple vulnerabilities in Adobe Reader 8.1.4
The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.
No detection rules found.
Talos
The Acrobat JavaScript Blocklist Framework
blogs_talos·2010-01-20
The Acrobat JavaScript Blocklist Framework
## The Acrobat JavaScript Blocklist Framework
Adobe recently announced and released the Adobe Reader and Acrobat JavaScript Blocklist Framework. I've had a little bit of time to play with it and would just like to share my thoughts. First of all, I am very pleased with this new blocklisting feature. Until now, when we knew about 0-day being actively exploited in the wild using JavaScript in some manner, we would just turn off JavaScript in Adobe products (Reader, Acrobat, etc...) all together. Personally, I could live without having JavaScript in my documents, but that's a totally different discussion. I understand why some people might want that feature for their PDF documents and why for them at least, turning JavaScript completely off would not be an option. So let's say, for example,
Talos
The Acrobat JavaScript Blocklist Framework
blogs_talos·2010-01-20
The Acrobat JavaScript Blocklist Framework
Adobe recently announced and released the Adobe Reader and Acrobat JavaScript Blocklist Framework. I've had a little bit of time to play with it and would just like to share my thoughts. First of all, I am very pleased with this new blocklisting feature. Until now, when we knew about 0-day being actively exploited in the wild using JavaScript in some manner, we would just turn off JavaScript in Adobe products (Reader, Acrobat, etc...) all together. Personally, I could live without having JavaScript in my documents, but that's a totally different discussion. I understand why some people might want that feature for their PDF documents and why for them at least, turning JavaScript completely off would not be an option. So let's say, for example, that you are running Adobe Reader 9.2.0 which i
Talos
Rule release for today - May 5th 2009
blogs_talos·2009-05-05·CVSS 9.3
CVE-2009-1492 [CRITICAL] Rule release for today - May 5th 2009
## Rule release for today - May 5th 2009
Adobe Reader Code Execution (CVE-2009-1492): The JavaScript API in Adobe Reader may allow a remote attacker to execute code on an affected system. The problem occurs when specially crafted JavaScript uses the getAnnots method in a PDF document.
A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 15493.
Adobe Reader Buffer Overflow (CVE-2009-1493): The JavaScript API in Adobe Reader may allow a remote attacker to execute code on an affected system. The problem occurs when specially crafted JavaScript uses the customDictionaryOpen method in a PDF document.
A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 15492.
Additi
Talos
Rule release for today - May 5th 2009
blogs_talos·2009-05-05·CVSS 9.3
CVE-2009-1492 [CRITICAL] Rule release for today - May 5th 2009
Adobe Reader Code Execution (CVE-2009-1492):
The JavaScript API in Adobe Reader may allow a remote attacker to execute code on an affected system. The problem occurs when specially crafted JavaScript uses the getAnnots method in a PDF document.
A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 15493.
Adobe Reader Buffer Overflow (CVE-2009-1493):
The JavaScript API in Adobe Reader may allow a remote attacker to execute code on an affected system. The problem occurs when specially crafted JavaScript uses the customDictionaryOpen method in a PDF document.
A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 15492.
Additionally as a result of ongoing research, th
Bugzilla
CVE-2009-1492, CVE-2009-1493 acroread: multiple vulnerabilities in Adobe Reader 8.1.4
bugzilla·2009-04-29·CVSS 9.3
CVE-2009-1492 [CRITICAL] CVE-2009-1492, CVE-2009-1493 acroread: multiple vulnerabilities in Adobe Reader 8.1.4
CVE-2009-1492, CVE-2009-1493 acroread: multiple vulnerabilities in Adobe Reader 8.1.4
Two vulnerabilities have been reported in Adobe Acrobat Reader 8.1.4 and 9.1.0 that can allow for the execution of arbitrary code as the user running Reader if javascript is enabled.
http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html
http://www.securityfocus.com/bid/34736
The first is a flaw in the getAnnots() function. The second is a flaw in the customDictionaryOpen() function.
Adobe is recommending that users disable javascript until an update becomes available.
Discussion:
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-1492 to
the following vulnerability:
Name: CVE-2009-1492
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1492
Assigned: 2009
http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.htmlhttp://blogs.adobe.com/psirt/2009/05/adobe_reader_issue_update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://osvdb.org/54129http://packetstorm.linuxsecurity.com/0904-exploits/spell.txthttp://secunia.com/advisories/34924http://secunia.com/advisories/35055http://secunia.com/advisories/35096http://secunia.com/advisories/35152http://secunia.com/advisories/35358http://secunia.com/advisories/35416http://secunia.com/advisories/35734http://security.gentoo.org/glsa/glsa-200907-06.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-259028-1http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=926953http://www.adobe.com/support/security/bulletins/apsb09-06.htmlhttp://www.kb.cert.org/vuls/id/970180http://www.redhat.com/support/errata/RHSA-2009-0478.htmlhttp://www.securityfocus.com/bid/34740http://www.securitytracker.com/id?1022139http://www.us-cert.gov/cas/techalerts/TA09-133B.htmlhttp://www.vupen.com/english/advisories/2009/1189http://www.vupen.com/english/advisories/2009/1317https://exchange.xforce.ibmcloud.com/vulnerabilities/50146https://www.exploit-db.com/exploits/8570http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.htmlhttp://blogs.adobe.com/psirt/2009/05/adobe_reader_issue_update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://osvdb.org/54129http://packetstorm.linuxsecurity.com/0904-exploits/spell.txthttp://secunia.com/advisories/34924http://secunia.com/advisories/35055http://secunia.com/advisories/35096http://secunia.com/advisories/35152http://secunia.com/advisories/35358http://secunia.com/advisories/35416http://secunia.com/advisories/35734http://security.gentoo.org/glsa/glsa-200907-06.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-259028-1http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=926953http://www.adobe.com/support/security/bulletins/apsb09-06.htmlhttp://www.kb.cert.org/vuls/id/970180http://www.redhat.com/support/errata/RHSA-2009-0478.htmlhttp://www.securityfocus.com/bid/34740http://www.securitytracker.com/id?1022139http://www.us-cert.gov/cas/techalerts/TA09-133B.htmlhttp://www.vupen.com/english/advisories/2009/1189http://www.vupen.com/english/advisories/2009/1317https://exchange.xforce.ibmcloud.com/vulnerabilities/50146https://www.exploit-db.com/exploits/8570
2009-04-30
Published
Exploited in the wild