This allows attackers to execute arbitrary code via a crafted document, related to a "cross document script execution vulnerability."
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-2101
The original article can be found at: http://www.securityfocus.com/bid/48255
Vulnerable Systems:
* Adobe Reader 9.3.4
* Adobe Reader 9.3.4
* Adobe Reader 9.3.3
* Adobe Reader 9.3.2
* Adobe Reader 9.3.1
* Adobe Reader 9.1.3
* Adobe Reader 9.1.2
* Adobe Reader 9.1.1
* Adobe Reader 8.2.6
* Adobe Reader 8.2.5
* Adobe Reader 8.2.4
* Adobe Reader 8.2.3
* Adobe Reader 8.2.2
* Adobe Reader 8.2.1
* Adobe Reader 8.1.7
* Adobe Reader 8.1.6
* Adobe Reader 8.1.5
* Adobe Reader 8.1.4
* Adobe Reader 8.1.3
* Adobe Reader 8.1.2
* Adobe Reader 8.1.1
* Adobe Reader 9.4.4
* Adobe Reader 9.4.3
* Adobe Reader 9.4.2
* Adobe Reader 9.4.1
* Adobe Reader 9.4
* Adobe Reader 9.3
* Adobe Reader 9.2
* Adobe Reader 9.1
* Adobe Reader 9
* Adobe Reader 9
* Adobe Reader 8.2
* Adobe Reader 8.1.2 Security Updat
* Adobe Reader 8.1
* Adobe Reader 8.0
* Adobe Reader 8
* Adobe Reader 10.0.3
* Adobe Reader 10.0.2
* Adobe Reader 10.0.1
* Adobe Reader 10.0
Immune Systems:
* Adobe Reader 9.4.5
* Adobe Reader 8.3
Adobe Reader and Acrobat are prone to an unspecified cross-domain scripting vulnerability.
A remote attacker can exploit this vulnerability to bypass the same-origin policy, execute arbitrary script code and obtain potentially sensitive information, or launch spoofing attacks against other sites.
Adobe Reader and Acrobat versions prior to 10.1 are affected.
Vendor Status:
Adobe as issued an update for this vulnerablity.
Patch Availability:
http://www.adobe.com/support/security/bulletins/apsb11-16.html
CVE Information:
CVE-2011-2101
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by