CVE-2017-2953: Buffer Overflow
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion module when processing a TIFF image. Successful exploitation could lead to arbitrary code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.020.20042 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.006.30244 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.0.18
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2953?
CVE-2017-2953 is categorized as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2017-2953?
To mitigate CVE-2017-2953, update Adobe Acrobat Reader to versions 11.0.19 or later or to the latest version of Adobe Acrobat DC.
What versions of Adobe Acrobat are affected by CVE-2017-2953?
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, and 11.0.18 and earlier are vulnerable to CVE-2017-2953.
What type of vulnerability is CVE-2017-2953?
CVE-2017-2953 is a memory corruption vulnerability specifically occurring in the image conversion module when processing TIFF images.
What impact does CVE-2017-2953 have on users?
Successful exploitation of CVE-2017-2953 can allow attackers to execute arbitrary code on the victim's system.