First published: Wed Jan 03 2007(Updated: )
Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, when used with Internet Explorer, Google Chrome, or Opera, allows remote attackers to cause a denial of service (memory consumption) via a long sequence of # (hash) characters appended to a PDF URL, related to a "cross-site scripting issue."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | =7.0.6 | |
Adobe Acrobat Reader | =7.0.5 | |
Adobe Acrobat Reader | =7.0.6 | |
Adobe Acrobat Reader | =7.0 | |
Adobe Acrobat Reader | =7.0 | |
Adobe Acrobat Reader | =7.0.8 | |
Adobe Acrobat Reader | =7.0.5 | |
Adobe Acrobat Reader | =6.0.3 | |
Adobe Acrobat Reader | <=7.0.8 | |
Adobe Acrobat 3d | ||
Adobe Acrobat Reader | =7.0.7 | |
Adobe Acrobat Reader | =7.0.3 | |
Adobe Acrobat Reader | =7.0.4 | |
Adobe Acrobat Reader | =7.0.6 | |
Adobe Acrobat Reader | =7.0.5 | |
Adobe Acrobat Reader | =7.0.3 | |
Adobe Acrobat Reader | =7.0.2 | |
Adobe Acrobat Reader | =7.0.1 | |
Adobe Acrobat Reader | =7.0.2 | |
Adobe Acrobat Reader | =7.0 | |
Adobe Acrobat Reader | =7.0.7 | |
Adobe Acrobat Reader | =7.0.8 | |
Adobe Acrobat Reader | =7.0.1 | |
Adobe Acrobat Reader | =6.0.1 | |
Adobe Acrobat Reader | =6.0.5 | |
Adobe Acrobat Reader | =7.0.7 | |
Adobe Acrobat Reader | =7.0.4 | |
Adobe Acrobat Reader | =7.0.8 | |
Adobe Acrobat Reader | =7.0.2 | |
Adobe Acrobat Reader | =6.0 | |
Adobe Acrobat Reader | =6.0.2 | |
Adobe Acrobat Reader | =7.0.3 | |
Adobe Acrobat Reader | =6.0.4 | |
Adobe Acrobat Reader | <=7.0.8 | |
Adobe Acrobat Reader | =7.0.4 | |
Adobe Acrobat Reader | =7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0048 is classified as a denial of service vulnerability affecting Adobe Acrobat Reader.
To mitigate CVE-2007-0048, users should upgrade to Adobe Acrobat Reader version 8.1.7 or later.
CVE-2007-0048 affects Adobe Acrobat Reader versions 7.x prior to 7.1.4 and 8.x prior to 8.1.7.
Yes, CVE-2007-0048 can be exploited remotely through the usage of malicious PDF files.
The impact of CVE-2007-0048 includes memory consumption that can lead to application crashes in Adobe Acrobat Reader.