CVE-2018-4893
published 2018-02-27CVE-2018-4893: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions…
medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of XPS font processing. A successful attack can lead to sensitive data exposure.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | 17.0 – 17.011.30070 | — |
| adobe | acrobat_dc | - – 18.009.20050 | — |
| adobe | acrobat_dc | 15.0 – 15.006.30394 | — |
| adobe | acrobat_reader | 17.0 – 17.011.30070 | — |
| adobe | acrobat_reader_dc | - – 18.009.20050 | — |
| adobe | acrobat_reader_dc | 15.0 – 15.006.30394 | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vulncheck6.5MEDIUM
GHSA
GHSA-fmch-mjf5-j6rj: An issue was discovered in Adobe Acrobat Reader 2018
ghsa_unreviewed·2022-05-14
CVE-2018-4893 [MEDIUM] CWE-125 GHSA-fmch-mjf5-j6rj: An issue was discovered in Adobe Acrobat Reader 2018
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of XPS font processing. A successful attack can lead to sensitive data exposure.
VulnCheck
Adobe Acrobat and Reader Out-of-bounds Read
vulncheck·2018·CVSS 6.5
CVE-2018-4893 [MEDIUM] Adobe Acrobat and Reader Out-of-bounds Read
Adobe Acrobat and Reader Out-of-bounds Read
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of XPS font processing. A successful attack can lead to sensitive data exposure.
Affected: Adobe Acrobat and Reader
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://go.recordedfuture.com/hubfs/reports/cta-2020-0603.pdf
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-02-27
Published