First published: Sat Mar 10 2007(Updated: )
AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followed by many %n sequences, a different vulnerability than CVE-2006-6027 and CVE-2006-6236.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Navigator | ||
Adobe Acrobat Reader Notification Manager | =8.0 | |
Firefox | =2.0.0.3 | |
Opera | =9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1377 is rated as a denial of service vulnerability impacting Adobe Reader 8.0 when accessed through certain browsers.
To mitigate CVE-2007-1377, users should upgrade to Adobe Reader 8.1 or later, as this version addresses the vulnerability.
CVE-2007-1377 affects Adobe Reader 8.0 and specific versions of browsers like Mozilla Firefox 2.0.0.3, Netscape, and Opera 9.2.
Yes, CVE-2007-1377 can be exploited remotely through a specially crafted PDF URL.
CVE-2007-1377 can enable a denial of service attack due to resource consumption when rendering affected PDF files.