CVE-2009-2979: Medium severity adobe acrobat reader vulnerability
Published Oct 19, 2009
·Updated
Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 do not properly perform XMP-XML entity expansion, which allows remote attackers to cause a denial of service via a crafted document.
Affected Software
50 affected components
Adobe Acrobat=8.0
Adobe Acrobat=8.1.2
Adobe Acrobat=7.0.2
Adobe Acrobat=7.0.3
Adobe Acrobat=7.1.0
Adobe Acrobat=7.0.8
Adobe Acrobat=7.1.1
Adobe Acrobat=8.1.1
Adobe Acrobat=8.1
Adobe Acrobat=9.0
Adobe Acrobat=7.0.6
Adobe Acrobat=7.0.7
Adobe Acrobat=9.1.1
Adobe Acrobat=7.1.3
Adobe Acrobat=8.1.4
Adobe Acrobat<=9.1.3
Adobe Acrobat=7.0.1
Adobe Acrobat=7.0.5
Adobe Acrobat=7.0.4
Adobe Acrobat=9.1.2
Adobe Acrobat=7.0.9
Adobe Acrobat=8.1.6
Adobe Acrobat=7.0
Adobe Acrobat=8.1.3
Adobe Acrobat reader=7.0.9
Adobe Acrobat reader<=9.1.3
Adobe Acrobat reader=8.1.6
Adobe Acrobat reader=7.1.3
Adobe Acrobat reader=7.0.5
Adobe Acrobat reader=7.0.6
Adobe Acrobat reader=7.1.0
Adobe Acrobat reader=9.1
Adobe Acrobat reader=7.0.8
Adobe Acrobat reader=8.0
Adobe Acrobat reader=7.0.7
Adobe Acrobat reader=9.1.2
Adobe Acrobat reader=8.1.5
Adobe Acrobat reader=7.0.3
Adobe Acrobat reader=9.1.1
Adobe Acrobat reader=7.0.1
Adobe Acrobat reader=7.0.2
Adobe Acrobat reader=7.0
Adobe Acrobat reader=8.1.4
Adobe Acrobat reader=8.1.2
Adobe Acrobat reader=9.0
Adobe Acrobat reader=8.1.1
Adobe Acrobat reader=8.1
Adobe Acrobat reader=8.1.3
Adobe Acrobat reader=7.1.1
Adobe Acrobat reader=7.0.4
Remediation
Patch Available
Patch Available
Event History
Oct 19, 2009
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2979?
CVE-2009-2979 has a severity rating that can lead to denial of service attacks.
2
How do I fix CVE-2009-2979?
To fix CVE-2009-2979, you should update Adobe Reader and Acrobat to versions 9.2 or later for major releases.
3
What types of systems are affected by CVE-2009-2979?
CVE-2009-2979 affects Adobe Reader and Acrobat versions 7.x, 8.x, and earlier versions of 9.x.
4
Can CVE-2009-2979 be exploited remotely?
Yes, CVE-2009-2979 can be exploited remotely via specially crafted documents sent to users.
5
What is XMP-XML entity expansion related to CVE-2009-2979?
XMP-XML entity expansion is a vulnerability that allows attackers to exploit the processing of XML data leading to denial of service.