CVE-2009-1493

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
30/04/2009
Last modified:
09/04/2025

Description

The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adobe:reader:8.1.4:*:*:*:*:*:*:*
cpe:2.3:a:adobe:reader:9.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools