Adobe Acrobat JOBOPTIONS Comment Parsing Out of Bounds Read

Strike ID:
E19-0w6t1
CVSS:
6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
False Positive:
f
Variants:
4
Year:
2019

Description

An out-of-bounds read vulnerability exists in several Adobe Acrobat products containing the 'acrodistdll.dll' shared library. The OOB read occurs whenever comments placed inside postscript objects are processed and no new line character is further detected. A remote attacker could exploit this vulnerability by enticing a user to open a maliciously crafted JOBOPTIONS file. Successful exploitation of this vulnerability could lead to information disclosure.

CVE

References