CVE-2013-2549
published 2013-03-11CVE-2013-2549: Unspecified vulnerability in Adobe Reader 11.0.02 allows remote attackers to execute arbitrary code via vectors related to a "break into the sandbox," as…
PriorityP348high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.42%
93.0th percentile
Unspecified vulnerability in Adobe Reader 11.0.02 allows remote attackers to execute arbitrary code via vectors related to a "break into the sandbox," as demonstrated by George Hotz during a Pwn2Own competition at CanSecWest 2013.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat_reader | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
acroread: Unspecified vulnerability allows remote attackers to execute arbitrary code (CanSecWest 2013)
vendor_redhat·2013-03-07·CVSS 7.5
CVE-2013-2549 [HIGH] acroread: Unspecified vulnerability allows remote attackers to execute arbitrary code (CanSecWest 2013)
acroread: Unspecified vulnerability allows remote attackers to execute arbitrary code (CanSecWest 2013)
Unspecified vulnerability in Adobe Reader 11.0.02 allows remote attackers to execute arbitrary code via vectors related to a "break into the sandbox," as demonstrated by George Hotz during a Pwn2Own competition at CanSecWest 2013.
GHSA
GHSA-f39f-hvgr-fwwx: Unspecified vulnerability in Adobe Reader 11
ghsa_unreviewed·2022-05-17
CVE-2013-2549 [HIGH] CWE-94 GHSA-f39f-hvgr-fwwx: Unspecified vulnerability in Adobe Reader 11
Unspecified vulnerability in Adobe Reader 11.0.02 allows remote attackers to execute arbitrary code via vectors related to a "break into the sandbox," as demonstrated by George Hotz during a Pwn2Own competition at CanSecWest 2013.
No detection rules found.
No public exploits indexed.
Bugzilla
acroread: multiple code execution flaws (APSB13-15)
bugzilla·2013-05-14·CVSS 7.5
CVE-2013-2718 [HIGH] acroread: multiple code execution flaws (APSB13-15)
acroread: multiple code execution flaws (APSB13-15)
Adobe security bulletin APSB13-15 describes multiple security flaws that could cause Adobe Acrobat Reader to crash and potentially allow an attacker to take control of the affected system:
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, CVE-2013-3341).
These updates resolve an integer underflow vulnerability that could lead to code execution (CVE-2013-2549).
These updates resolve a stack overflow vulnerability that could lead to code executio
Bugzilla
CVE-2013-2549 acroread: Unspecified vulnerability allows remote attackers to execute arbitrary code (CanSecWest 2013)
bugzilla·2013-03-11·CVSS 7.5
CVE-2013-2549 [HIGH] CVE-2013-2549 acroread: Unspecified vulnerability allows remote attackers to execute arbitrary code (CanSecWest 2013)
CVE-2013-2549 acroread: Unspecified vulnerability allows remote attackers to execute arbitrary code (CanSecWest 2013)
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2549 to the following vulnerability:
Unspecified vulnerability in Adobe Reader 11.0.02 allows remote attackers to execute arbitrary code via vectors related to a "break into the sandbox," as demonstrated by George Hotz during a Pwn2Own competition at CanSecWest 2013.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2549
[2] http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157
[3] http://twitter.com/thezdi/statuses/309771882612281344
Discussion:
Statement:
(none)
---
This issue has been addressed in following products:
Supplementary for Red Hat Ente
http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0826.htmlhttp://security.gentoo.org/glsa/glsa-201308-03.xmlhttp://twitter.com/thezdi/statuses/309771882612281344http://www.adobe.com/support/security/bulletins/apsb13-15.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16809http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0826.htmlhttp://security.gentoo.org/glsa/glsa-201308-03.xmlhttp://twitter.com/thezdi/statuses/309771882612281344http://www.adobe.com/support/security/bulletins/apsb13-15.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16809
2013-03-11
Published