CVE-2009-1859
published 2009-06-11CVE-2009-1859: Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to…
PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
7.16%
93.6th percentile
Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
acroread: multiple security fixes in version 8.1.6 (APSB09-07)
vendor_redhat·2009-06-09·CVSS 9.3
CVE-2009-1859 [CRITICAL] acroread: multiple security fixes in version 8.1.6 (APSB09-07)
acroread: multiple security fixes in version 8.1.6 (APSB09-07)
Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
GHSA
GHSA-vgm3-w345-pp4f: Adobe Reader 7 and Acrobat 7 before 7
ghsa_unreviewed·2022-05-02
CVE-2009-1859 [HIGH] GHSA-vgm3-w345-pp4f: Adobe Reader 7 and Acrobat 7 before 7
Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
No detection rules found.
No public exploits indexed.
Talos
DojoSec Adobe bug fixed
blogs_talos·2009-06-30·CVSS 9.3
CVE-2009-1859 [CRITICAL] DojoSec Adobe bug fixed
Well I've been busy, AFA 2009 CyberSpace Symposium, tracking down cool crashes, booking DefCon travel, and my job (herding cats at Sourcefire World Domination HQ). But better late than never right?
June 9th, Adobe released
http://www.adobe.com/support/security/bulletins/apsb09-07.html
Which was described as
"This update resolves a memory corruption vulnerability that could potentially lead to code execution (CVE-2009-1859)."
This was the bug found during my DojoSec talk back in April, which was entitled: 1 Byte , 5 Minutes , Holy Hot Tuna (see it here: http://vimeo.com/4110571. This bug was really more like "1 Byte, 9 Minutes, this looks really difficult to make reliable."
Additionally it's covered by Snort Rule SID 15562
Talos
DojoSec Adobe bug fixed
blogs_talos·2009-06-30·CVSS 9.3
CVE-2009-1859 [CRITICAL] DojoSec Adobe bug fixed
## DojoSec Adobe bug fixed
Well I've been busy, AFA 2009 CyberSpace Symposium, tracking down cool crashes, booking DefCon travel, and my job (herding cats at Sourcefire World Domination HQ). But better late than never right?
June 9th, Adobe released
http://www.adobe.com/support/security/bulletins/apsb09-07.html
Which was described as
"This update resolves a memory corruption vulnerability that could potentially lead to code execution (CVE-2009-1859)."
This was the bug found during my DojoSec talk back in April, which was entitled: 1 Byte , 5 Minutes , Holy Hot Tuna (see it here: http://vimeo.com/4110571 . This bug was really more like "1 Byte, 9 Minutes, this looks really difficult to make reliable."
Additionally it's covered by Snort Rule SID 15562
Talos
Rule release for today - June 12th 2009
blogs_talos·2009-06-13·CVSS 9.3
CVE-2009-1859 [CRITICAL] Rule release for today - June 12th 2009
## Rule release for today - June 12th 2009
Adobe Acrobat and Reader Remote Vulnerability (CVE-2009-1859): Adobe Acrobat and Acrobat Reader contain programming errors that may allow a remote attacker to execute code on a vulnerable system. The errors occur in the processing of embedded image files in a PDF document.
A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 15562.
Symantec Alert Management System Buffer Overflow (CVE-2009-1430): The Symantec Alert Management System contains multiple vulnerabilities that may allow a remote attacker to execute code on an affected system.
A rule to detect attacks targeting these vulnerabilities is included in this release and is identified with GID 1, SID 15555.
Symantec Alert Manag
Talos
Rule release for today - June 12th 2009
blogs_talos·2009-06-13·CVSS 9.3
CVE-2009-1859 [CRITICAL] Rule release for today - June 12th 2009
Adobe Acrobat and Reader Remote Vulnerability (CVE-2009-1859):
Adobe Acrobat and Acrobat Reader contain programming errors that may allow a remote attacker to execute code on a vulnerable system. The errors occur in the processing of embedded image files in a PDF document.
A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 15562.
Symantec Alert Management System Buffer Overflow (CVE-2009-1430):
The Symantec Alert Management System contains multiple vulnerabilities that may allow a remote attacker to execute code on an affected system.
A rule to detect attacks targeting these vulnerabilities is included in this release and is identified with GID 1, SID 15555.
Symantec Alert Management System Code Execution (CVE-2009-1431):
Bugzilla
acroread: multiple security fixes in version 8.1.6 (APSB09-07)
bugzilla·2009-06-10·CVSS 9.3
CVE-2009-1855 [CRITICAL] acroread: multiple security fixes in version 8.1.6 (APSB09-07)
acroread: multiple security fixes in version 8.1.6 (APSB09-07)
Adobe has published a security bulletin APSB09-07 for security issues addressed in Adobe Reader and Acrobat products:
http://www.adobe.com/support/security/bulletins/apsb09-07.html
Quoting Adobe bulletin APSB09-07 for issues descriptions:
This update resolves a stack overflow vulnerability that could
potentially lead to code execution (CVE-2009-1855).
This update resolves an integer overflow that leads to a Denial of
Service (DoS); arbitrary code execution has not been demonstrated,
but may be possible (CVE-2009-1856).
This update resolves a memory corruption vulnerability that leads
to a Denial of Service (DoS); arbitrary code execution has not been
demonstrated, but may be possible (CVE-2009-1857).
This update resolves
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://secunia.com/advisories/34580http://secunia.com/advisories/35496http://secunia.com/advisories/35655http://secunia.com/advisories/35685http://secunia.com/advisories/35734http://security.gentoo.org/glsa/glsa-200907-06.xmlhttp://securitytracker.com/id?1022361http://www.adobe.com/support/security/bulletins/apsb09-07.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1109.htmlhttp://www.securityfocus.com/bid/35274http://www.securityfocus.com/bid/35289http://www.us-cert.gov/cas/techalerts/TA09-161A.htmlhttp://www.vupen.com/english/advisories/2009/1547http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://secunia.com/advisories/34580http://secunia.com/advisories/35496http://secunia.com/advisories/35655http://secunia.com/advisories/35685http://secunia.com/advisories/35734http://security.gentoo.org/glsa/glsa-200907-06.xmlhttp://securitytracker.com/id?1022361http://www.adobe.com/support/security/bulletins/apsb09-07.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1109.htmlhttp://www.securityfocus.com/bid/35274http://www.securityfocus.com/bid/35289http://www.us-cert.gov/cas/techalerts/TA09-161A.htmlhttp://www.vupen.com/english/advisories/2009/1547
2009-06-11
Published