CVE-2009-0658


Published: 20-02-2009
Updated: 28-04-2009

Product:
adobe: reader 8.1.1
adobe: reader 8.1.2
adobe: acrobat_reader 4.0.5
adobe: acrobat_reader 4.0.5a
adobe: acrobat_reader 4.0.5c
adobe: acrobat_reader 4.5
adobe: acrobat_reader 5.0
adobe: acrobat_reader 5.0.10
adobe: acrobat_reader 5.0.11
adobe: acrobat_reader 5.0.5
adobe: acrobat_reader 5.0.6
adobe: acrobat_reader 5.0.7
adobe: acrobat_reader 5.0.9
adobe: acrobat_reader 5.1
adobe: acrobat_reader 6.0
adobe: acrobat_reader 6.0.1
adobe: acrobat_reader 6.0.2
adobe: acrobat_reader 6.0.3
adobe: acrobat_reader 6.0.4
adobe: acrobat_reader 6.0.5
adobe: acrobat_reader 7.0
adobe: acrobat_reader 7.0.1
adobe: acrobat_reader 7.0.2
adobe: acrobat_reader 7.0.3
adobe: acrobat_reader 7.0.4
adobe: acrobat_reader 7.0.5
adobe: acrobat_reader 7.0.6
adobe: acrobat_reader 7.0.7
adobe: acrobat_reader 7.0.8
adobe: acrobat_reader 7.0.9
adobe: acrobat_reader 8.0
adobe: acrobat_reader 8.1
adobe: acrobat_reader 8.1.1
adobe: acrobat_reader 8.1.2
adobe: acrobat_reader 9

Severity: High (9.3)

CVSS vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C)

Attack`s vector: Victim must voluntarily interact with attack mechanism

Potential loss type: Integrity, Confidentiality, Availability

Vulnerability description:
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.

Patch available: No

References:
CERT: http://www.us-cert.gov/cas/techalerts/TA09-051A.html
CERT-VN: http://www.kb.cert.org/vuls/id/905281
XF: http://xforce.iss.net/xforce/xfdb/48825
VUPEN: http://www.vupen.com/english/advisories/2009/1019
MISC: http://www.symantec.com/security_response/writeup.jsp?docid=2009-02121 ...
MISC: http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090219
SECTRACK: http://www.securitytracker.com/id?1021739
BID: http://www.securityfocus.com/bid/33751
REDHAT: http://www.redhat.com/support/errata/RHSA-2009-0376.html
MILW0RM: http://www.milw0rm.com/exploits/8099
MILW0RM: http://www.milw0rm.com/exploits/8090
FRSIRT: http://www.frsirt.com/english/advisories/2009/0472
CONFIRM: http://www.adobe.com/support/security/bulletins/apsb09-04.html
CONFIRM: http://www.adobe.com/support/security/advisories/apsa09-01.html
SUNALERT: http://sunsolve.sun.com/search/document.do?assetkey=1-66-256788-1
GENTOO: http://security.gentoo.org/glsa/glsa-200904-17.xml
SECUNIA: http://secunia.com/advisories/34790
SECUNIA: http://secunia.com/advisories/34706
SECUNIA: http://secunia.com/advisories/34490
SECUNIA: http://secunia.com/advisories/34392
SECUNIA: http://secunia.com/advisories/33901
OVAL: http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:de ...
OSVDB: http://osvdb.org/52073
SUSE: http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010. ...
SUSE: http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005. ...
MISC: http://isc.sans.org/diary.html?n&storyid=5902

Cisco Security Advisory: Cisco Security Agent Remote Code Execution Vulnerabilities

Cisco Security Agent is affected by vulnerabilities that could allow an unauthenticated attacker to ...

27 october, 2011

Cisco Security Advisory: Denial of Service Vulnerability in Cisco Video Surveillance IP Cameras

A denial of service (DoS) vulnerability exists in the Cisco Video Surveillance IP Cameras 24 ...

27 october, 2011

Cisco Security Advisory: Cisco Unified Contact Center Express Directory Traversal Vulnerability

Cisco Unified Contact Center Express (UCCX or Unified CCX) and Cisco Unified IP Interactive ...

27 october, 2011

MS12-016: Vulnerabilities in .NET Framework and Microsoft Silverlight Could Allow Remote Code Execution (2651026)

This security update resolves one publicly disclosed vulnerability and one privately reported vulner ...

15 february, 2012

MS12-015: Vulnerabilities in Microsoft Visio Viewer 2010 Could Allow Remote Code Execution (2663510)

This security update resolves five privately reported vulnerabilities in Microsoft Office.

15 february, 2012

MS12-014: Vulnerability in Indeo Codec Could Allow Remote Code Execution (2661637)

This security update resolves one publicly disclosed vulnerability in Microsoft Windows.

15 february, 2012

CVE-2012-0206

common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response.

CVE-2011-5081

Cross-site scripting (XSS) vulnerability in RestoreFile.pm in BackupPC 3.1.0, 3.2.1, and possibly other earlier versions allows remote attackers to inject arbitrary web script or HTML via the share parameter in a RestoreFile action to index.cgi.

CVE-2011-4923

Cross-site scripting (XSS) vulnerability in View.pm in BackupPC 3.0.0, 3.1.0, 3.2.0, 3.2.1, and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the num parameter in a view action to index.cgi, related to the log file viewer, a different vulnerability than CVE-2011-3361.

CVE-2011-4614

PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, 4.6.x before 4.6.2, and development versions of 4.7 allows remote attackers to execute arbitrary PHP code via a URL in the BACK_PATH parameter.

CVE-2011-4320

The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publish tag that lacks a node attribute.

CVE-2011-4113

SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."

CVE-2011-4105

LightDM before 1.0.6 allows local users to change ownership of arbitrary files via a symlink attack on ~/.Xauthority.

CVE-2011-3361

Cross-site scripting (XSS) vulnerability in CGI/Browse.pm in BackupPC 3.2.0 and possibly other versions before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the num parameter in a browse action to index.cgi.

CVE-2012-1200

Multiple PHP remote file inclusion vulnerabilities in Nova CMS allow remote attackers to execute arbitrary PHP code via a URL in the (1) fileType parameter to optimizer/index.php, (2) id parameter to administrator/modules/moduleslist.php, (3) filename parameter to includes/function/gets.php, or (4) conf[blockfile] parameter to includes/function/usertpl.php.

CVE-2012-1199

Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) BASE_path parameter to base_ag_main.php, (2) base_db_setup.php, (3) base_graph_common.php, (4) base_graph_display.php, (5) base_graph_form.php, (6) base_graph_main.php, (7) base_local_rules.php, (8) base_logout.php, (9) base_main.php, (10) base_maintenance.php, (11) base_payload.php, (12) base_qry_alert.php, (13) base_qry_common.php, (14) base_qry_main.php, (15) base_stat_alerts.php, (16) base_stat_class.php, (17) base_stat_common.php, (18) base_stat_ipaddr.php, (19) base_stat_iplink.php, (20) base_stat_ports.php, (21) base_stat_sensor.php, (22) base_stat_time.php, (23) base_stat_uaddr.php, (24) base_user.php, (25) index.php, (26) admin/base_roleadmin.php, (27) admin/base_useradmin.php, (28) admin/index.php, (29) help/base_setup_help.php, (30) includes/base_action.inc.php, (31) includes/base_cach!  e.inc.php, (32) includes/base_db.inc.php, (33) includes/base_db.inc.php, (34) includes/base_include.inc.php, (35) includes/base_output_html.inc.php, (36) includes/base_output_query.inc.php, (37) includes/base_state_criteria.inc.php, (38) includes/base_state_query.inc.php or (39) setup/base_conf_contents.php; (40) GLOBALS[user_session_path] parameter to includes/base_state_common.inc.php; (41) BASE_Language parameter to setup/base_conf_contents.php; or (42) ado_inc_php parameter to setup/setup2.php.

CVE-2012-1198

base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents of the file with an executable extension via a create action, then accessing it via a view action.

CVE-2012-1197

Integer overflow in the IDE_ACDStd.apl module for ACDSee 14.1 Build 137 allows remote attackers to execute arbitrary code via crafted "image dimension values" in a BMP file, which triggers a heap-based buffer overflow.

CVE-2012-1196

Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary files via a .. (dot dot) in the filename parameter in a SetTaskLogByFile SOAP request.

CVE-2012-1195

Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a PutUpdateFileCore command in a RunAMTCommand SOAP request, then accessing the file via a direct request to the file in the web root.

CVE-2012-1194

The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

This Alert covers CVE-2010-0896 for the mail component of the Sun Convergence product

This Sun Alert covers CVE-2010-0896 for the mail component of the Sun Convergence product.

14 april, 2010

This Alert Covers CVE-2010-0893 for the Mail Component of the Sun Convergence Product

This Alert covers CVE-2010-0893 for the mail component of the Sun Convergence product.

14 april, 2010

SunOS 5.10_x86: ucode driver patch

6905530 processor microcode code can panic when retrieving microcode revision.

02 february, 2010

[RHSA-2010:1003-01] Moderate: git security update

Red Hat Security Advisory - Moderate: git security update

21 december, 2010

[RHSA-2010:1002-01] Moderate: mod_auth_mysql security update

Red Hat Security Advisory - Moderate: mod_auth_mysql security update

21 december, 2010

[RHSA-2010:1000-01] Important: bind security update

Red Hat Security Advisory - Important: bind security update

20 december, 2010

ASUS Net4Switch ipswcom.dll ActiveX Buffer Overflow PoC

Target: Net4Switch ipswcom ActiveX Control 1.0.0020
Impact: Code execution

Adobe Flash Player MP4 SequenceParameterSetNALUnit Buffer Overflow Exploit (meta)

Target: Adobe Flash Player версии до 10.3.181.36
Impact: Code execution

MS12-004 midiOutPlayNextPolyEvent Heap Overflow Exploit

Target: Microsoft Windows Media
Impact: Code execution