First published: Wed Jul 15 2015(Updated: )
Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5096 and CVE-2015-5105.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=10.0<=10.1.14 | |
Adobe Acrobat Reader | >=11.0.0<=11.0.11 | |
Adobe Acrobat DC | >=15.006.30033<15.006.30060 | |
Adobe Acrobat DC | >=15.007.20033<15.008.20082 | |
Adobe Acrobat Reader | >=10.0<=10.1.14 | |
Adobe Acrobat Reader | >=11.0.0<=11.0.11 | |
Adobe Acrobat DC | >=15.006.30033<15.006.30060 | |
Adobe Acrobat DC | >=15.007.20033<15.008.20082 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-5098 is classified as critical due to its potential for arbitrary code execution.
To fix CVE-2015-5098, users should upgrade to the latest version of Adobe Reader or Acrobat as specified in the vendor's security advisory.
CVE-2015-5098 affects Adobe Reader and Acrobat versions 10.x before 10.1.15, 11.x before 11.0.12, and various DC versions prior to specified updates.
CVE-2015-5098 is a heap-based buffer overflow vulnerability.
Yes, CVE-2015-5098 can potentially be exploited remotely if a user opens a malicious PDF file.