CVE-2012-1530Improper Restriction of Operations within the Bounds of a Memory Buffer in Adobe Acrobat

Severity
10.0CRITICALNVD
EPSS
21.6%
top 4.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateMay 17

Description

Heap-based buffer overflow in the XSLT engine in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing an XSL file that triggers memory corruption when the lang function processes XML data with a crafted node-set.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages18 packages

NVDadobe/acrobat_reader32 versions+31
NVDadobe/acrobat32 versions+31

Patches

🔴Vulnerability Details

7
GHSA
GHSA-897j-c2px-h972: Adobe Reader and Acrobat 92022-05-17
GHSA
GHSA-532h-q782-w73v: Adobe Reader and Acrobat 92022-05-17
GHSA
GHSA-j52q-7rp8-wgfj: Adobe Reader and Acrobat 92022-05-17
GHSA
GHSA-qr3r-9qvv-xj4c: Adobe Reader and Acrobat 92022-05-17
GHSA
GHSA-gj65-qwj7-4qg8: Heap-based buffer overflow in the XSLT engine in Adobe Reader and Acrobat 92022-05-17

📋Vendor Advisories

10
Red Hat
acroread: multiple code execution flaws (APSB13-02)2013-01-08
Red Hat
acroread: multiple code execution flaws (APSB13-02)2013-01-08
Red Hat
acroread: multiple code execution flaws (APSB13-02)2013-01-08
Red Hat
acroread: multiple code execution flaws (APSB13-02)2013-01-08
Red Hat
acroread: multiple code execution flaws (APSB13-02)2013-01-08

💬Community

2
Bugzilla
acroread: multiple code execution flaws (APSB13-02)2013-01-09
Bugzilla
CVE-2011-4110 kernel: keys: NULL pointer deref in the user-defined key type2011-11-04
CVE-2012-1530 — Adobe Acrobat vulnerability | cvebase