CVE-2009-0658

High PUBLISHED

Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF...

Adobe · Reader

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
7.8 High

At a Glance

Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.

java
CVE Published
Feb 20, 2009
Exploitation Reported
Feb 20, 2009
CVSS
7.8 High
EPSS
Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • RHSA-2009:0376 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2009-0376.html
  • SUSE-SA:2009:014 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005...
  • 256788 sunsolve.sun.com · Vendor Advisory http://sunsolve.sun.com/search/document.do?assetkey=1-66-256788-1
  • GLSA-200904-17 security.gentoo.org · Vendor Advisory http://security.gentoo.org/glsa/glsa-200904-17.xml
  • SUSE-SR:2009:009 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010...
Show 21 more references
  • 34790 secunia.com · Third-Party Advisory http://secunia.com/advisories/34790
  • TA09-051A us-cert.gov · Third-Party Advisory http://www.us-cert.gov/cas/techalerts/TA09-051A.html
  • 34490 secunia.com · Third-Party Advisory http://secunia.com/advisories/34490
  • 33901 secunia.com · Third-Party Advisory http://secunia.com/advisories/33901
  • 34392 secunia.com · Third-Party Advisory http://secunia.com/advisories/34392
  • 34706 secunia.com · Third-Party Advisory http://secunia.com/advisories/34706
  • ADV-2009-0472 vupen.com · Third-Party Advisory http://www.vupen.com/english/advisories/2009/0472
  • VU#905281 kb.cert.org · Third-Party Advisory http://www.kb.cert.org/vuls/id/905281
  • 8099 exploit-db.com · Exploit https://www.exploit-db.com/exploits/8099
  • 8090 exploit-db.com · Exploit https://www.exploit-db.com/exploits/8090
  • oval:org.mitre.oval:def:5697 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
  • 52073 osvdb.org · VDB Entry http://osvdb.org/52073
  • 33751 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/33751
  • adobe-acrobat-reader-image-bo(48825) exchange.xforce.ibmcloud.com · VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/48825
  • 1021739 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1021739
  • ADV-2009-1019 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2009/1019
  • shadowserver.org/wiki/pmwiki.php shadowserver.org · CVE Record http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090219
  • adobe.com/support/security/bulletins/apsb09-04.html adobe.com · CVE Record http://www.adobe.com/support/security/bulletins/apsb09-04.html
  • isc.sans.org/diary.html isc.sans.org · CVE Record http://isc.sans.org/diary.html?n&storyid=5902
  • adobe.com/support/security/advisories/apsa09-01.html adobe.com · CVE Record http://www.adobe.com/support/security/advisories/apsa09-01.html
  • symantec.com/security_response/writeup.jsp symantec.com · CVE Record http://www.symantec.com/security_response/writeup.jsp?docid=2009-0212...

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.