First published: Thu Apr 28 2005(Updated: )
** UNVERIFIABLE ** NOTE: this issue describes a problem that can not be independently verified as of 20050421. Adobe Acrobat reader (AcroRd32.exe) 6.0 and earlier allows remote attackers to cause a denial of service ("Invalid-ID-Handle-Error" error) and modify memory beginning at a particular address, possibly allowing the execution of arbitrary code, via a crafted PDF file. NOTE: the vendor has stated that the reporter refused to provide sufficient details to confirm the issue. In addition, due to the lack of details in the original advisory, an independent verification is not possible. Finally, the reliability of the original reporter is unknown. This item has only been assigned a CVE identifier for tracking purposes, and to serve as a concrete example of the newly defined UNVERIFIABLE and PRERELEASE content decisions in CVE, which must be discussed by the Editorial Board. Without additional details or independent verification by reliable sources, it is highly likely that this item will be REJECTED.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | =5.0.10 | |
Adobe Acrobat Reader | =3.0 | |
Adobe Acrobat Reader | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1347 is classified as a denial of service vulnerability that affects Adobe Acrobat Reader versions 3.0, 5.0.10, and 6.0.
To mitigate CVE-2005-1347, it is recommended to upgrade to a newer version of Adobe Acrobat Reader that is not affected by this vulnerability.
CVE-2005-1347 allows remote attackers to cause a denial of service through an 'Invalid-ID-Handle-Error' in the affected versions of Adobe Acrobat Reader.
CVE-2005-1347 affects Adobe Acrobat Reader versions 3.0, 5.0.10, and 6.0.
CVE-2005-1347 is noted as an unverifiable issue as of the last update, making independent validation difficult.