First published: Tue Apr 15 2014(Updated: )
The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to execute arbitrary code via a crafted PDF document, a related issue to CVE-2012-6636.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | <=11.1.3 | |
Adobe Acrobat Reader | =11.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0514 is rated as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2014-0514, update Adobe Reader Mobile to version 11.2 or later for Android.
CVE-2014-0514 is associated with remote code execution attacks via crafted PDF documents.
Adobe Reader Mobile versions prior to 11.2 for Android, including 11.1.0 and below, are affected by CVE-2014-0514.
Yes, CVE-2014-0514 can potentially be exploited through crafted PDF files that do not require user interaction to execute malicious code.