CVE-2008-2992: Adobe Reader and Acrobat Input Validation Vulnerability
Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.
Other sources
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2992?
CVE-2008-2992 has a critical severity level due to its potential for remote code execution.
How do I fix CVE-2008-2992?
To fix CVE-2008-2992, update Adobe Acrobat and Reader to the latest version beyond 8.1.2.
What are the affected versions for CVE-2008-2992?
CVE-2008-2992 affects Adobe Acrobat and Reader versions 8.1.2 and earlier, along with several earlier 7.x and 6.x versions.
Can CVE-2008-2992 be exploited remotely?
Yes, CVE-2008-2992 can be exploited remotely via malicious PDF files.
What type of vulnerability is CVE-2008-2992?
CVE-2008-2992 is an input validation issue that leads to a stack-based buffer overflow.