CVE-2009-2997: Buffer Overflow
Published Oct 19, 2009
·Updated
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.
Affected Software
50 affected components
Adobe Acrobat=8.0
Adobe Acrobat=8.1.2
Adobe Acrobat=7.0.2
Adobe Acrobat=7.0.3
Adobe Acrobat=7.1.0
Adobe Acrobat=7.0.8
Adobe Acrobat=7.1.1
Adobe Acrobat=8.1.1
Adobe Acrobat=8.1
Adobe Acrobat=9.0
Adobe Acrobat=7.0.6
Adobe Acrobat=7.0.7
Adobe Acrobat=9.1.1
Adobe Acrobat=7.1.3
Adobe Acrobat=8.1.4
Adobe Acrobat<=9.1.3
Adobe Acrobat=7.0.1
Adobe Acrobat=7.0.5
Adobe Acrobat=7.0.4
Adobe Acrobat=9.1.2
Adobe Acrobat=7.0.9
Adobe Acrobat=8.1.6
Adobe Acrobat=7.0
Adobe Acrobat=8.1.3
Adobe Acrobat reader=7.0.9
Adobe Acrobat reader<=9.1.3
Adobe Acrobat reader=8.1.6
Adobe Acrobat reader=7.1.3
Adobe Acrobat reader=7.0.5
Adobe Acrobat reader=7.0.6
Adobe Acrobat reader=7.1.0
Adobe Acrobat reader=9.1
Adobe Acrobat reader=7.0.8
Adobe Acrobat reader=8.0
Adobe Acrobat reader=7.0.7
Adobe Acrobat reader=9.1.2
Adobe Acrobat reader=8.1.5
Adobe Acrobat reader=7.0.3
Adobe Acrobat reader=9.1.1
Adobe Acrobat reader=7.0.1
Adobe Acrobat reader=7.0.2
Adobe Acrobat reader=7.0
Adobe Acrobat reader=8.1.4
Adobe Acrobat reader=8.1.2
Adobe Acrobat reader=9.0
Adobe Acrobat reader=8.1.1
Adobe Acrobat reader=8.1
Adobe Acrobat reader=8.1.3
Adobe Acrobat reader=7.1.1
Adobe Acrobat reader=7.0.4
Remediation
Patch Available
Patch Available
Event History
Oct 19, 2009
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2997?
CVE-2009-2997 is considered a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2009-2997?
To fix CVE-2009-2997, you should update Adobe Reader and Acrobat to the latest version available.
3
What versions of Adobe are affected by CVE-2009-2997?
CVE-2009-2997 affects Adobe Reader and Acrobat versions prior to 7.1.4, 8.1.7, and 9.2.
4
What kind of attack can exploit CVE-2009-2997?
CVE-2009-2997 can be exploited through unspecified vectors that could allow attackers to execute arbitrary code.
5
Is there a workaround for CVE-2009-2997?
There are no effective workarounds for CVE-2009-2997; the only solution is to apply the appropriate updates.