First published: Sun Dec 03 2006(Updated: )
Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the (1) src, (2) setPageMode, (3) setLayoutMode, and (4) setNamedDest methods in an AcroPDF ActiveX control, a different set of vectors than CVE-2006-6027.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader Notification Manager | =7.0 | |
Adobe Acrobat Reader Notification Manager | =7.0.1 | |
Adobe Acrobat Reader Notification Manager | =7.0.2 | |
Adobe Acrobat Reader Notification Manager | =7.0.3 | |
Adobe Acrobat Reader Notification Manager | =7.0.4 | |
Adobe Acrobat Reader Notification Manager | =7.0.5 | |
Adobe Acrobat Reader Notification Manager | =7.0.6 | |
Adobe Acrobat Reader Notification Manager | =7.0.7 | |
Adobe Acrobat Reader Notification Manager | =7.0.8 | |
=7.0 | ||
=7.0.1 | ||
=7.0.2 | ||
=7.0.3 | ||
=7.0.4 | ||
=7.0.5 | ||
=7.0.6 | ||
=7.0.7 | ||
=7.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6236 is considered a high-severity vulnerability due to its potential to cause denial of service and execute arbitrary code.
The recommended fix for CVE-2006-6236 is to upgrade Adobe Acrobat Reader to a version later than 7.0.8.
CVE-2006-6236 affects Adobe Acrobat Reader versions 7.0 to 7.0.8.
Exploitation of CVE-2006-6236 could lead to denial of service and the execution of arbitrary code on the affected system.
If updating Adobe Acrobat Reader is not possible, consider disabling the AcroPDF ActiveX control or restricting its use in your environment.