CVE-2013-0622
published 2013-01-10CVE-2013-0622: Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to bypass intended access restrictions via unspecified…
PriorityP348critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.68%
92.2th percentile
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-0624.
Affected
64 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: sock_diag: out-of-bounds access to sock_diag_handlers[]
vendor_redhat·2013-02-24·CVSS 7.2
CVE-2013-1763 [HIGH] CWE-129 kernel: sock_diag: out-of-bounds access to sock_diag_handlers[]
kernel: sock_diag: out-of-bounds access to sock_diag_handlers[]
Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows local users to gain privileges via a large family value in a Netlink message.
Statement: This issue did not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5 and 6.
This issue was addressed in Red Hat Enterprise MRG 2 via RHSA-2013:0622 https://rhn.redhat.com/errata/RHSA-2013-0622.html
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Red Hat
acroread: security bypass flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0622 [CRITICAL] acroread: security bypass flaws (APSB13-02)
acroread: security bypass flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-0624.
Statement: Not Vulnerable. This issue does not affect the version of acroread as shipped with Red Hat Enterprise Linux 5 and 6.
Package: acroread (Red Hat Enterprise Linux 5) - Not affected
Package: acroread (Red Hat Enterprise Linux 6) - Not affected
Red Hat
acroread: security bypass flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0624 [CRITICAL] acroread: security bypass flaws (APSB13-02)
acroread: security bypass flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-0622.
Statement: Not Vulnerable. This issue does not affect the version of acroread as shipped with Red Hat Enterprise Linux 5 and 6.
Package: acroread (Red Hat Enterprise Linux 5) - Not affected
Package: acroread (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-4627-4rjp-mw63: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2013-0622 [CRITICAL] GHSA-4627-4rjp-mw63: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-0624.
GHSA
GHSA-6hfq-vff3-j8jm: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2013-0624 [CRITICAL] GHSA-6hfq-vff3-j8jm: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-0622.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1763 kernel: sock_diag: out-of-bounds access to sock_diag_handlers[]
bugzilla·2013-02-24·CVSS 7.2
CVE-2013-1763 [HIGH] CVE-2013-1763 kernel: sock_diag: out-of-bounds access to sock_diag_handlers[]
CVE-2013-1763 kernel: sock_diag: out-of-bounds access to sock_diag_handlers[]
Description:
An unprivileged user can send a netlink message resulting in an out-of-bounds access of the sock_diag_handlers[] array which, in turn, allows userland to take over control while in kernel mode.
References:
http://seclists.org/oss-sec/2013/q1/420
http://thread.gmane.org/gmane.linux.network/260061
Upstream fix:
http://thread.gmane.org/gmane.linux.network/260061
Discussion:
Created kernel tracking bugs for this issue
Affects: fedora-all [bug 915057]
---
Statement:
This issue did not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5 and 6.
This issue was addressed in Red Hat Enterprise MRG 2 via RHSA-2013:0622 https://rhn.redhat.com/errata/RHSA-2013-0622.html
Bugzilla
CVE-2013-0622 CVE-2013-0624 acroread: security bypass flaws (APSB13-02)
bugzilla·2013-01-09·CVSS 10.0
CVE-2013-0622 [CRITICAL] CVE-2013-0622 CVE-2013-0624 acroread: security bypass flaws (APSB13-02)
CVE-2013-0622 CVE-2013-0624 acroread: security bypass flaws (APSB13-02)
Adobe security bulletin APSB13-02 describes two security flaws that could cause Adobe Acrobat Reader to bypass intended security restrictions:
These updates resolve security bypass vulnerabilities (CVE-2013-0622, CVE-2013-0624).
External References:
http://www.adobe.com/support/security/bulletins/apsb13-02.html
Discussion:
Statement:
Not Vulnerable. This issue does not affect the version of acroread as shipped with Red Hat Enterprise Linux 5 and 6.
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00081.htmlhttp://security.gentoo.org/glsa/glsa-201308-03.xmlhttp://www.adobe.com/support/security/bulletins/apsb13-02.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16484http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00028.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00081.htmlhttp://security.gentoo.org/glsa/glsa-201308-03.xmlhttp://www.adobe.com/support/security/bulletins/apsb13-02.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16484
2013-01-10
Published