CVE-2016-1067HTTP Request/Response Splitting in Adobe Acrobat

Severity
9.8CRITICALNVD
GHSA6.1
EPSS
2.5%
top 14.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 11
Latest updateMay 17

Description

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1045, CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1051, CVE-2016-1052, CVE-2016-1053, CVE-2016-1054, CVE-2016-1055, CVE-2016-1056, CVE-

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

NVDadobe/acrobat_reader_dc15.006.30121+1
NVDadobe/acrobat11.0.15
NVDadobe/acrobat_dc15.006.30121+1
NVDadobe/acrobat_xi11.0.15
NVDadobe/reader11.0.15

Patches

🔴Vulnerability Details

59
GHSA
GHSA-26cr-cjf8-cfmg: Use-after-free vulnerability in Adobe Reader and Acrobat before 112022-05-17
GHSA
GHSA-4gmc-h534-mxc2: Use-after-free vulnerability in Adobe Reader and Acrobat before 112022-05-17
GHSA
GHSA-242x-jrhr-gh88: Use-after-free vulnerability in Adobe Reader and Acrobat before 112022-05-17
GHSA
GHSA-j27w-c382-3ccp: Use-after-free vulnerability in Adobe Reader and Acrobat before 112022-05-17
GHSA
GHSA-5q75-39qf-22f7: Use-after-free vulnerability in Adobe Reader and Acrobat before 112022-05-17

📋Vendor Advisories

1
Red Hat
undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)2018-04-25

🕵️Threat Intelligence

1
Zscaler
Zscaler found Multiple Security Vulnerabilities | 05-13-2016

💬Community

2
Bugzilla
CVE-2018-1067 wildfly: undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]2018-06-19
Bugzilla
CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)2018-03-01
CVE-2016-1067 — HTTP Request/Response Splitting | cvebase