Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-4369 | First vendor Publication | 2011-12-16 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4369 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:14865 | |||
Oval ID: | oval:org.mitre.oval:def:14865 | ||
Title: | Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011. | ||
Description: | Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2011-4369 | Version: | 10 |
Platform(s): | Microsoft Windows 7 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows Server 2003 Microsoft Windows XP Microsoft Windows 2000 | Product(s): | Adobe Acrobat Adobe Reader |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:20865 | |||
Oval ID: | oval:org.mitre.oval:def:20865 | ||
Title: | RHSA-2012:0011: acroread security update (Critical) | ||
Description: | Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2012:0011-01 CVE-2011-2462 CVE-2011-4369 | Version: | 29 |
Platform(s): | Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 5 | Product(s): | acroread |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:22868 | |||
Oval ID: | oval:org.mitre.oval:def:22868 | ||
Title: | DEPRECATED: ELSA-2012:0011: acroread security update (Critical) | ||
Description: | Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2012:0011-01 CVE-2011-2462 CVE-2011-4369 | Version: | 13 |
Platform(s): | Oracle Linux 6 Oracle Linux 5 | Product(s): | acroread |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:23694 | |||
Oval ID: | oval:org.mitre.oval:def:23694 | ||
Title: | ELSA-2012:0011: acroread security update (Critical) | ||
Description: | Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2012:0011-01 CVE-2011-2462 CVE-2011-4369 | Version: | 13 |
Platform(s): | Oracle Linux 6 Oracle Linux 5 | Product(s): | acroread |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-08-02 | Name : SuSE Update for acroread openSUSE-SU-2012:0087-1 (acroread) File : nvt/gb_suse_2012_0087_1.nasl |
2012-02-12 | Name : Gentoo Security Advisory GLSA 201201-19 (acroread) File : nvt/glsa_201201_19.nasl |
2011-12-09 | Name : Adobe Reader/Acrobat 'U3D' Component Memory Corruption Vulnerability - Mac OS X File : nvt/gb_adobe_prdts_u3d_mem_crptn_vuln_macosx.nasl |
2011-12-09 | Name : Adobe Reader/Acrobat 'U3D' Component Memory Corruption Vulnerability - Windows File : nvt/gb_adobe_prdts_u3d_mem_crptn_vuln_win.nasl |
2011-12-09 | Name : Adobe Reader 'U3D' Component Memory Corruption Vulnerability - Linux File : nvt/gb_adobe_reader_u3d_mem_crptn_vuln_lin.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
78026 | Adobe Reader / Acrobat PRC Component Remote Memory Corruption A memory corruption flaw exists in Adobe Reader and Acrobat. The PRC component fails to sanitize user-supplied input when handling certain data, resulting in memory corruption. With a specially crafted PDF file, a context-dependent attacker can execute arbitrary code. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Adobe Acrobat Reader PRC file MarkupLinkedItem arbitrary code execution attempt RuleID : 20802 - Revision : 10 - Type : FILE-PDF |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2012-33.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : suse_11_3_acroread-120111.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : suse_11_4_acroread-120111.nasl - Type : ACT_GATHER_INFO |
2012-01-31 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201201-19.nasl - Type : ACT_GATHER_INFO |
2012-01-18 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_acroread-120112.nasl - Type : ACT_GATHER_INFO |
2012-01-18 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_acroread-7924.nasl - Type : ACT_GATHER_INFO |
2012-01-11 | Name : The version of Adobe Acrobat on the remote Windows host is affected by multip... File : adobe_acrobat_apsb12-01.nasl - Type : ACT_GATHER_INFO |
2012-01-11 | Name : The version of Adobe Reader on the remote Windows host is affected by multipl... File : adobe_reader_apsb12-01.nasl - Type : ACT_GATHER_INFO |
2012-01-11 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2012-0011.nasl - Type : ACT_GATHER_INFO |
2011-12-07 | Name : The version of Adobe Acrobat on the remote Windows host is affected by multip... File : adobe_acrobat_apsa11-04.nasl - Type : ACT_GATHER_INFO |
2011-12-07 | Name : The version of Adobe Reader on the remote Windows host is affected by multipl... File : adobe_reader_apsa11-04.nasl - Type : ACT_GATHER_INFO |
2011-12-07 | Name : The version of Adobe Reader on the remote Mac OS X host is affected by a memo... File : macosx_adobe_reader_apsa11-04.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:03:19 |
|
2024-11-28 12:27:48 |
|
2020-05-23 00:32:13 |
|
2017-09-19 09:25:06 |
|
2016-06-29 00:23:39 |
|
2016-04-26 21:14:15 |
|
2016-03-18 13:26:06 |
|
2014-06-14 13:31:57 |
|
2014-02-17 11:06:16 |
|
2014-01-19 21:28:13 |
|
2013-05-10 23:10:52 |
|
2013-01-30 13:21:07 |
|