CVE-2019-7809
published 2019-05-22CVE-2019-7809: Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier…
medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat_dc | 15.006.30060 – 15.006.30495 | — |
| adobe | acrobat_dc | 15.008.20082 – 19.010.20100 | — |
| adobe | acrobat_dc | 17.011.30056 – 17.011.30140 | — |
| adobe | acrobat_reader_dc | 15.006.30060 – 15.006.30493 | — |
| adobe | acrobat_reader_dc | 15.008.20082 – 19.010.20099 | — |
| adobe | acrobat_reader_dc | 17.011.30059 – 17.011.30138 | — |
| adobe | adobe_acrobat_and_reader | — | — |
GHSA
GHSA-8p2q-qjw9-pw64: Adobe Acrobat and Reader versions 2019
ghsa_unreviewed·2022-05-24
CVE-2019-7809 [HIGH] GHSA-8p2q-qjw9-pw64: Adobe Acrobat and Reader versions 2019
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
Red Hat
struts2: predictable generation of form submission token
vendor_redhat·2014-12-08·CVSS 6.8
CVE-2014-7809 [MEDIUM] CWE-330 struts2: predictable generation of form submission token
struts2: predictable generation of form submission token
Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable values, which allows remote attackers to bypass the CSRF protection mechanism.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in some products' source code packages. The inclusion was part of an import of the Google Guice repository, which includes struts2-core. Customers that build artefacts from our source code could be at risk. Re
No detection rules found.
No public exploits indexed.
Trendmicro
Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
blogs_trendmicro·2019-05-15·CVSS 9.8
CVE-2019-0708 [CRITICAL] Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
Sfruttamento vulnerabilità
## Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
Microsoft’s May security release includes updates for 80 vulnerabilities for a number of Microsoft products, including a security update for unsupported operating systems such as Windows XP and Server 2003.
By: Trend Micro Research May 15, 2019 Read time: ( words)
Save to Folio
Update as of 5/17/2019 10:15AM PHT: Added rules for CVE-2019-0708 in Trend Micro Deep Security and Tipping Point.
Microsoft’s May security release includes updates for 80 vulnerabilities for a number of Microsoft products, including a security update for unsupported operating systems such as Windows XP and Server 2003 not included in the mainstream customer support notification. Of the security vulnerabilities fixed in this releas
Trendmicro
Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
blogs_trendmicro·2019-05-15·CVSS 9.8
CVE-2019-0708 [CRITICAL] Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
Exploits & Vulnerabilities
# Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
Microsoft’s May security release includes updates for 80 vulnerabilities for a number of Microsoft products, including a security update for unsupported operating systems such as Windows XP and Server 2003.
By: Trend Micro Research
2019/05/15
Read time: ( words)
Save to Folio
Update as of 5/17/2019 10:15AM PHT: Added rules for CVE-2019-0708 in Trend Micro Deep Security and Tipping Point.
Microsoft’s May security release includes updates for 80 vulnerabilities for a number of Microsoft products, including a security update for unsupported operating systems such as Windows XP and Server 2003 not included in the mainstream customer support notification. Of the security vulnerabilities fixed in this release,
Trendmicro
Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
blogs_trendmicro·2019-05-15·CVSS 9.8
CVE-2019-0708 [CRITICAL] Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
Exploits & Vulnerabilities
## Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
Microsoft’s May security release includes updates for 80 vulnerabilities for a number of Microsoft products, including a security update for unsupported operating systems such as Windows XP and Server 2003.
By: Trend Micro Research May 15, 2019 Read time: ( words)
Save to Folio
Update as of 5/17/2019 10:15AM PHT: Added rules for CVE-2019-0708 in Trend Micro Deep Security and Tipping Point.
Microsoft’s May security release includes updates for 80 vulnerabilities for a number of Microsoft products, including a security update for unsupported operating systems such as Windows XP and Server 2003 not included in the mainstream customer support notification. Of the security vulnerabilities fixed in this releas
Trendmicro
Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
blogs_trendmicro·2019-05-15·CVSS 9.8
CVE-2019-0708 [CRITICAL] Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
Exploits & Vulnerabilities
## Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
Microsoft’s May security release includes updates for 80 vulnerabilities for a number of Microsoft products, including a security update for unsupported operating systems such as Windows XP and Server 2003.
By: Trend Micro Research 2019/05/15 Read time: ( words)
Save to Folio
Update as of 5/17/2019 10:15AM PHT: Added rules for CVE-2019-0708 in Trend Micro Deep Security and Tipping Point.
Microsoft’s May security release includes updates for 80 vulnerabilities for a number of Microsoft products, including a security update for unsupported operating systems such as Windows XP and Server 2003 not included in the mainstream customer support notification. Of the security vulnerabilities fixed in this release,
Trendmicro
Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
blogs_trendmicro·2019-05-15·CVSS 9.8
CVE-2019-0708 [CRITICAL] Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
Exploits & Vulnerabilities
# Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
Microsoft’s May security release includes updates for 80 vulnerabilities for a number of Microsoft products, including a security update for unsupported operating systems such as Windows XP and Server 2003.
By: Trend Micro Research
May 15, 2019
Read time: ( words)
Save to Folio
Update as of 5/17/2019 10:15AM PHT: Added rules for CVE-2019-0708 in Trend Micro Deep Security and Tipping Point.
Microsoft’s May security release includes updates for 80 vulnerabilities for a number of Microsoft products, including a security update for unsupported operating systems such as Windows XP and Server 2003 not included in the mainstream customer support notification. Of the security vulnerabilities fixed in this releas
Trendmicro
Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
blogs_trendmicro·2019-05-15·CVSS 9.8
CVE-2019-0708 [CRITICAL] Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
Ausnutzung von Schwachstellen
## Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
Microsoft’s May security release includes updates for 80 vulnerabilities for a number of Microsoft products, including a security update for unsupported operating systems such as Windows XP and Server 2003.
By: Trend Micro Research May 15, 2019 Read time: ( words)
Save to Folio
Update as of 5/17/2019 10:15AM PHT: Added rules for CVE-2019-0708 in Trend Micro Deep Security and Tipping Point.
Microsoft’s May security release includes updates for 80 vulnerabilities for a number of Microsoft products, including a security update for unsupported operating systems such as Windows XP and Server 2003 not included in the mainstream customer support notification. Of the security vulnerabilities fixed in this rel
Trendmicro
Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
blogs_trendmicro·2019-05-15·CVSS 9.8
CVE-2019-0708 [CRITICAL] Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
Exploits y vulnerabilidades
## Patch Tuesday: Fixes for 'Wormable' Flaw, Zero-Day
Microsoft’s May security release includes updates for 80 vulnerabilities for a number of Microsoft products, including a security update for unsupported operating systems such as Windows XP and Server 2003.
By: Trend Micro Research May 15, 2019 Read time: ( words)
Save to Folio
Update as of 5/17/2019 10:15AM PHT: Added rules for CVE-2019-0708 in Trend Micro Deep Security and Tipping Point.
Microsoft’s May security release includes updates for 80 vulnerabilities for a number of Microsoft products, including a security update for unsupported operating systems such as Windows XP and Server 2003 not included in the mainstream customer support notification. Of the security vulnerabilities fixed in this relea
Bugzilla
CVE-2014-7809 struts2: predictable generation of form submission token
bugzilla·2014-12-09·CVSS 6.8
CVE-2014-7809 [MEDIUM] CVE-2014-7809 struts2: predictable generation of form submission token
CVE-2014-7809 struts2: predictable generation of form submission token
It was found that the Struts 2 Random Number Generator component generates predictable form submission tokens. A remote attacker able to acquire a victim's form submission token could predict the next value of this token and perform Cross-Site Request Forgery (CSRF) attacks against that victim.
This flaw is reported to affect Struts 2.0.0 through 2.3.16.3. It is corrected in Struts 2.3.20.
External References:
https://cwiki.apache.org/confluence/display/WW/S2-023
Discussion:
Statement:
A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, u
http://www.securityfocus.com/bid/108320https://helpx.adobe.com/security/products/acrobat/apsb19-18.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-19-500/http://www.securityfocus.com/bid/108320https://helpx.adobe.com/security/products/acrobat/apsb19-18.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-19-500/
2019-05-22
Published