CVE-2009-0658
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 88%
from disclosure to weapon480 days
Published on NVDFeb 20
1st PoC+480d
metasploitFeb 19
VulnCheckFeb 20
exploitation probability
88%top 1% of all CVEs
observed exploitation
yesVulnCheck
5 public exploit(s)
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Fixed
10 products (20 components)
Red Hat Desktop version 3 Extras · Red Hat Desktop version 4 Extras · Red Hat Enterprise Linux AS version 3 Extras · Red Hat Enterprise Linux AS version 4 Extras · Red Hat Enterprise Linux Desktop Supplementary (v. 5) · and others 5
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.
Affected products
n/a · n/apublic PoCs found — 5✓ VexDay Proof
cve_reference✓ VexDay Proofwww.exploit-db.com/exploits/8099exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/16672exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/16593githubgithub.com/kyaw-tun/blue-team-capstone★ 0cve_referencewww.exploit-db.com/exploits/8090unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://isc.sans.org/diary.html?n&storyid=5902http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.htmlhttp://osvdb.org/52073http://secunia.com/advisories/33901http://secunia.com/advisories/34392http://secunia.com/advisories/34490http://secunia.com/advisories/34706http://secunia.com/advisories/34790http://security.gentoo.org/glsa/glsa-200904-17.xmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/48825https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5697