First published: Fri Jan 30 2015(Updated: )
CoolType.dll in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows, and 10.x through 10.1.13 and 11.x through 11.0.10 on OS X, allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted PDF document.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader Notification Manager | =10.1.13 | |
Adobe Acrobat Reader Notification Manager | =11.0.10 | |
Apple iOS and macOS | ||
Adobe Acrobat Reader | =10.0 | |
Adobe Acrobat Reader | =10.0.1 | |
Adobe Acrobat Reader | =10.0.2 | |
Adobe Acrobat Reader | =10.0.3 | |
Adobe Acrobat Reader | =10.1 | |
Adobe Acrobat Reader | =10.1.1 | |
Adobe Acrobat Reader | =10.1.2 | |
Adobe Acrobat Reader | =10.1.3 | |
Adobe Acrobat Reader | =10.1.4 | |
Adobe Acrobat Reader | =10.1.5 | |
Adobe Acrobat Reader | =10.1.6 | |
Adobe Acrobat Reader | =10.1.7 | |
Adobe Acrobat Reader | =10.1.8 | |
Adobe Acrobat Reader | =10.1.9 | |
Adobe Acrobat Reader | =10.1.10 | |
Adobe Acrobat Reader | =10.1.11 | |
Adobe Acrobat Reader | =10.1.12 | |
Adobe Acrobat Reader | =11.0 | |
Adobe Acrobat Reader | =11.0.1 | |
Adobe Acrobat Reader | =11.0.2 | |
Adobe Acrobat Reader | =11.0.3 | |
Adobe Acrobat Reader | =11.0.4 | |
Adobe Acrobat Reader | =11.0.5 | |
Adobe Acrobat Reader | =11.0.6 | |
Adobe Acrobat Reader | =11.0.7 | |
Adobe Acrobat Reader | =11.0.8 | |
Adobe Acrobat Reader | =11.0.9 | |
Microsoft Windows | ||
Adobe Acrobat Reader | =10.1.13 | |
Adobe Acrobat Reader | =11.0.10 | |
Adobe Acrobat Reader Notification Manager | =10.0 | |
Adobe Acrobat Reader Notification Manager | =10.0.1 | |
Adobe Acrobat Reader Notification Manager | =10.0.2 | |
Adobe Acrobat Reader Notification Manager | =10.0.3 | |
Adobe Acrobat Reader Notification Manager | =10.1 | |
Adobe Acrobat Reader Notification Manager | =10.1.1 | |
Adobe Acrobat Reader Notification Manager | =10.1.2 | |
Adobe Acrobat Reader Notification Manager | =10.1.3 | |
Adobe Acrobat Reader Notification Manager | =10.1.4 | |
Adobe Acrobat Reader Notification Manager | =10.1.5 | |
Adobe Acrobat Reader Notification Manager | =10.1.6 | |
Adobe Acrobat Reader Notification Manager | =10.1.7 | |
Adobe Acrobat Reader Notification Manager | =10.1.8 | |
Adobe Acrobat Reader Notification Manager | =10.1.9 | |
Adobe Acrobat Reader Notification Manager | =10.1.10 | |
Adobe Acrobat Reader Notification Manager | =10.1.11 | |
Adobe Acrobat Reader Notification Manager | =10.1.12 | |
Adobe Acrobat Reader Notification Manager | =11.0.0 | |
Adobe Acrobat Reader Notification Manager | =11.0.01 | |
Adobe Acrobat Reader Notification Manager | =11.0.02 | |
Adobe Acrobat Reader Notification Manager | =11.0.03 | |
Adobe Acrobat Reader Notification Manager | =11.0.04 | |
Adobe Acrobat Reader Notification Manager | =11.0.05 | |
Adobe Acrobat Reader Notification Manager | =11.0.06 | |
Adobe Acrobat Reader Notification Manager | =11.0.07 | |
Adobe Acrobat Reader Notification Manager | =11.0.08 | |
Adobe Acrobat Reader Notification Manager | =11.0.09 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9161 is classified as a medium severity vulnerability that can cause a denial of service via crafted PDF documents.
To fix CVE-2014-9161, you should update Adobe Reader and Acrobat to version 10.1.13 or 11.0.10 or later.
CVE-2014-9161 affects Adobe Reader versions 10.x before 10.1.13 and 11.x before 11.0.10.
CVE-2014-9161 primarily results in a denial of service rather than direct data loss, but it could potentially lead to other impacts.
Yes, CVE-2014-9161 can be exploited remotely through specially crafted PDF documents.