TTCSIRT-222.082719: TT-CSIRT Advisory – Adobe Security Updates
Adobe has released a security update stating that the following issues have been discovered in Adobe Acrobat and Reader:
a) Multiple Out-of-Bounds Read vulnerabilities that could allow for information disclosure – (CVE-2019-8077).
b) A command injection vulnerability that could allow for arbitrary code execution – (CVE-2019-8060).
c) Multiple heap overflow vulnerabilities that could allow for privilege escalation – (CVE-2019-7832).
d) Multiple integer overflow vulnerabilities that could allow for information disclosure – (CVE-2019-8099).
e) A type confusion vulnerability could allow for arbitrary code execution – (CVE-2019-8019).
Successful exploitation of the most severe of these vulnerabilities could result in the attacker gaining control of the affected system and depending on the privileges associated with the user, an attacker could then install programs; view, change or delete data; or create new accounts with full user rights.
Further information on these vulnerabilities and how they can be mitigated can be found on the Adobe Website at https://helpx.adobe.com/security/products/acrobat/apsb19-41.html |