First published: Sat Dec 09 2017(Updated: )
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a type confusion overflow vulnerability in the graphics rendering engine.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | <=11.0.22 | |
Adobe Acrobat Reader | >=17.0<=17.011.30066 | |
Adobe Acrobat | >=-<=17.012.20098 | |
Adobe Acrobat | >=15.0<=15.006.30355 | |
Adobe Acrobat Reader | <=11.0.22 | |
Adobe Acrobat Reader | >=17.0<=17.011.30066 | |
Adobe Acrobat Reader | >=-<=17.012.20098 | |
Adobe Acrobat Reader | >=15.0<=15.006.30355 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16379 has been classified as critical due to its potential to allow for remote code execution.
To fix CVE-2017-16379, you should update to the latest versions of Adobe Acrobat and Reader.
CVE-2017-16379 affects Adobe Acrobat and Reader versions 11.0.22 and earlier, as well as several specified versions of Acrobat DC.
CVE-2017-16379 is a type confusion overflow vulnerability that can be exploited in the graphics rendering process.
If updates cannot be applied, it is advisable to limit the use of Adobe Acrobat and Reader, particularly with untrusted documents.