CVE-2011-0567Improper Restriction of Operations within the Bounds of a Memory Buffer in Adobe Acrobat

Severity
9.3CRITICALNVD
EPSS
14.1%
top 5.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10
Latest updateMay 14

Description

AcroRd32.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image that triggers an incorrect pointer calculation, leading to heap memory corruption, a different vulnerability than CVE-2011-0566 and CVE-2011-0603.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDadobe/acrobat_reader27 versions+26
NVDadobe/acrobat28 versions+27

Patches

🔴Vulnerability Details

3
GHSA
GHSA-94hh-vfrm-jc8h: Adobe Reader and Acrobat 102022-05-14
GHSA
GHSA-3c6p-4f52-2c76: Adobe Reader and Acrobat 102022-05-14
GHSA
GHSA-qvcw-45h8-6h3w: AcroRd322022-05-14

📋Vendor Advisories

3
Red Hat
acroread: critical APSB11-032011-02-08
Red Hat
acroread: critical APSB11-032011-02-08
Red Hat
acroread: critical APSB11-032011-02-08

💬Community

1
Bugzilla
CVE-2011-0562 CVE-2011-0563 CVE-2011-0565 CVE-2011-0566 CVE-2011-0567 CVE-2011-0585 CVE-2011-0586 CVE-2011-0589 CVE-2011-0590 CVE-2011-0591 CVE-2011-0592 CVE-2011-0593 CVE-2011-0594 CVE-2011-0595 acro2011-02-08
CVE-2011-0567 — Adobe Acrobat vulnerability | cvebase