CVE-2010-2887: Critical severity Adobe Acrobat reader vulnerability
Published Oct 6, 2010
·Updated
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat 9.x before 9.4 on Linux allow attackers to gain privileges via unknown vectors.
Affected Software
22 affected components
Adobe Acrobat reader=9.2
Adobe Acrobat reader=9.1
Adobe Acrobat reader=9.1.3
Adobe Acrobat reader=9.1.2
Adobe Acrobat reader=9.3.3
Adobe Acrobat reader=9.1.1
Adobe Acrobat reader=9.3.4
Adobe Acrobat reader=9.3
Adobe Acrobat reader=9.0
Adobe Acrobat reader=9.3.2
Adobe Acrobat reader=9.3.1
Adobe Acrobat=9.3.3
Adobe Acrobat=9.2
Adobe Acrobat=9.1
Adobe Acrobat=9.0
Adobe Acrobat=9.3.4
Adobe Acrobat=9.3.2
Adobe Acrobat=9.1.1
Adobe Acrobat=9.3.1
Adobe Acrobat=9.1.2
Adobe Acrobat=9.1.3
Adobe Acrobat=9.3
Remediation
Event History
Oct 6, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
Which installations are affected?
Adobe Reader and Acrobat 9.x on Linux are affected when running versions earlier than 9.4.
2
Does exploitation require authentication or local access?
No authentication is required, and the network attack vector indicates an attacker can exploit the issue remotely. The stated attack complexity is medium.
3
What is the recommended remediation?
Apply the available patch by updating affected Adobe Reader or Acrobat installations to version 9.4 or later.