CVE-2005-0492: Input Validation
Published Feb 21, 2005
·Updated
Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page node.
Affected Software
2 affected components
Adobe Acrobat reader=6.0.3
Adobe Acrobat reader=7.0
Remediation
Patch Available
Event History
Feb 21, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0492?
CVE-2005-0492 has been classified as a denial of service vulnerability which can cause Adobe Acrobat Reader to crash.
2
How does CVE-2005-0492 affect Adobe Acrobat Reader?
CVE-2005-0492 allows remote attackers to crash Adobe Acrobat Reader by sending a specially crafted PDF file.
3
Which versions of Adobe Acrobat Reader are affected by CVE-2005-0492?
CVE-2005-0492 affects Adobe Acrobat Reader versions 6.0.3 and 7.0.0.
4
Can CVE-2005-0492 be exploited remotely?
Yes, CVE-2005-0492 can be exploited remotely through malicious PDF files.
5
Is there a way to mitigate the risk associated with CVE-2005-0492?
To mitigate the risk from CVE-2005-0492, users should update to a secure version of Adobe Acrobat Reader that is not vulnerable.