Adobe.Reader.CollectEmailInfo

NameAdobe.Reader.CollectEmailInfo.JavaScript.Method.Buffer.Overflow
Release DateFeb 15, 2008
SeverityCritical
ImpactSystem Compromise: remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attempt to exploit a buffer overflow vulnerability in the Adobe PDF reader JavaScript engine.

By passing overly long parameters to the method "Collab.collectEmailInfo()", an attacker can execute arbitrary code on a vulnerable computer. To exploit this the attacker must trick the victim into opening a maliciously crafted PDF document.
Affected ProductsVersions older than Adobe Reader and Acrobat before 8.1.2
Recommended ActionsUpdate to at least version 8.1.2
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5659
http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0655
Reference/shttp://www.vupen.com/english/advisories/2008/0425 (FrSIRT)
http://www.zerodayinitiative.com/advisories/ZDI-08-004.html
Reference: VID-15393