Security Advisory

CVE-2009-1492

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-04-30 20:00:00
Last updated 2024-08-07 05:13:25
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.