CVE-2008-4817: Input Validation
The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, triggering heap corruption.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4817?
CVE-2008-4817 is considered a critical vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2008-4817?
To mitigate CVE-2008-4817, update Adobe Acrobat Professional and Reader to version 8.1.3 or later.
What types of software are affected by CVE-2008-4817?
CVE-2008-4817 affects Adobe Acrobat Reader and Adobe Acrobat Professional versions up to and including 8.1.2.
How does CVE-2008-4817 exploit heap corruption?
CVE-2008-4817 exploits heap corruption by using a crafted PDF document that invokes an AcroJS function with a long string argument.
What are the potential consequences of CVE-2008-4817?
Exploitation of CVE-2008-4817 may lead to remote code execution, data manipulation, or system compromise.