First published: Tue Nov 21 2006(Updated: )
Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX control.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader Notification Manager | =7.0 | |
Adobe Acrobat Reader Notification Manager | =7.0.1 | |
Adobe Acrobat Reader Notification Manager | =7.0.2 | |
Adobe Acrobat Reader Notification Manager | =7.0.3 | |
Adobe Acrobat Reader Notification Manager | =7.0.4 | |
Adobe Acrobat Reader Notification Manager | =7.0.5 | |
Adobe Acrobat Reader Notification Manager | =7.0.6 | |
Adobe Acrobat Reader Notification Manager | =7.0.7 | |
Adobe Acrobat Reader Notification Manager | =7.0.8 | |
=7.0 | ||
=7.0.1 | ||
=7.0.2 | ||
=7.0.3 | ||
=7.0.4 | ||
=7.0.5 | ||
=7.0.6 | ||
=7.0.7 | ||
=7.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6027 is classified as a denial of service vulnerability that may allow remote code execution.
To mitigate CVE-2006-6027, upgrade to a later version of Adobe Reader that is not affected by this vulnerability.
Adobe Reader versions 7.0 through 7.0.8 are affected by CVE-2006-6027.
Yes, CVE-2006-6027 can be exploited remotely via a malicious argument string sent to the LoadFile method.
Exploitation of CVE-2006-6027 could lead to a denial of service or possibly executing arbitrary code on the victim's machine.