CVE-2009-2998: Input Validation
Published Oct 19, 2009
·Updated
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-3458.
Affected Software
50 affected components
Adobe Acrobat=7.0
Adobe Acrobat=7.0.1
Adobe Acrobat=7.0.2
Adobe Acrobat=7.0.3
Adobe Acrobat=7.0.4
Adobe Acrobat=7.0.5
Adobe Acrobat=7.0.6
Adobe Acrobat=7.0.7
Adobe Acrobat=7.0.8
Adobe Acrobat=7.0.9
Adobe Acrobat=7.1.0
Adobe Acrobat=7.1.1
Adobe Acrobat=7.1.3
Adobe Acrobat=8.0
Adobe Acrobat=8.1
Adobe Acrobat=8.1.1
Adobe Acrobat=8.1.2
Adobe Acrobat=8.1.3
Adobe Acrobat=8.1.4
Adobe Acrobat=8.1.6
Adobe Acrobat=9.0
Adobe Acrobat=9.1.1
Adobe Acrobat=9.1.2
Adobe Acrobat=9.1.3
Adobe Acrobat reader<=9.1.3
Adobe Acrobat reader=7.0
Adobe Acrobat reader=7.0.1
Adobe Acrobat reader=7.0.2
Adobe Acrobat reader=7.0.3
Adobe Acrobat reader=7.0.4
Adobe Acrobat reader=7.0.5
Adobe Acrobat reader=7.0.6
Adobe Acrobat reader=7.0.7
Adobe Acrobat reader=7.0.8
Adobe Acrobat reader=7.0.9
Adobe Acrobat reader=7.1.0
Adobe Acrobat reader=7.1.1
Adobe Acrobat reader=7.1.3
Adobe Acrobat reader=8.0
Adobe Acrobat reader=8.1
Adobe Acrobat reader=8.1.1
Adobe Acrobat reader=8.1.2
Adobe Acrobat reader=8.1.3
Adobe Acrobat reader=8.1.4
Adobe Acrobat reader=8.1.5
Adobe Acrobat reader=8.1.6
Adobe Acrobat reader=9.0
Adobe Acrobat reader=9.1
Adobe Acrobat reader=9.1.1
Adobe Acrobat reader=9.1.2
Remediation
Patch Available
Patch Available
Event History
Oct 19, 2009
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2998?
CVE-2009-2998 is rated as critical due to the potential for arbitrary code execution.
2
How do I fix CVE-2009-2998?
To fix CVE-2009-2998, update Adobe Reader and Acrobat to version 7.1.4, 8.1.7, or 9.2 or later.
3
What software versions are affected by CVE-2009-2998?
CVE-2009-2998 affects Adobe Reader and Acrobat versions 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2.
4
What types of attacks can exploit CVE-2009-2998?
CVE-2009-2998 may allow attackers to execute arbitrary code via unspecified vectors.
5
Is there a workaround for CVE-2009-2998?
The best approach is to apply the available security updates to mitigate the risk of exploitation from CVE-2009-2998.