CVE-2009-0658
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 88%
from disclosure to weapon480 days
Published on NVDFeb 20
1st PoC+480d
metasploitFeb 19
VulnCheckFeb 20
exploitation probability
88%top 1% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.
Affected products
n/a · n/apublic PoCs found — 4✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/16672cve_reference✓ VexDay Proofwww.exploit-db.com/exploits/8099exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/16593cve_referencewww.exploit-db.com/exploits/8090unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://isc.sans.org/diary.html?n&storyid=5902http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.htmlhttp://osvdb.org/52073http://secunia.com/advisories/33901http://secunia.com/advisories/34392http://secunia.com/advisories/34490http://secunia.com/advisories/34706http://secunia.com/advisories/34790http://security.gentoo.org/glsa/glsa-200904-17.xmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/48825https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5697