CVE-2008-4812

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
05/11/2008
Last modified:
30/10/2018

Description

Array index error in Adobe Reader and Acrobat, and the Explorer extension (aka AcroRd32Info), 8.1.2, 8.1.1, and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that triggers an out-of-bounds write, related to parsing of Type 1 fonts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adobe:acrobat:*:unknown:3d:*:*:*:*:* 8.1.2 (including)
cpe:2.3:a:adobe:acrobat:*:unknown:professional:*:*:*:*:* 8.1.2 (including)
cpe:2.3:a:adobe:acrobat:*:unknown:standard:*:*:*:*:* 8.1.2 (including)
cpe:2.3:a:adobe:acrobat:8.1.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:8.1.1:unknown:3d:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:8.1.1:unknown:professional:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:8.1.1:unknown:standard:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* 8.0 (including)