Show plain JSON{"id": "CVE-2017-16381", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 9.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C", "authentication": "NONE", "integrityImpact": "COMPLETE", "accessComplexity": "MEDIUM", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 8.8, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 2.8}]}, "published": "2017-12-09T06:29:01.677", "references": [{"url": "http://www.securityfocus.com/bid/101831", "tags": ["Third Party Advisory", "VDB Entry"], "source": "psirt@adobe.com"}, {"url": "http://www.securitytracker.com/id/1039791", "tags": ["Third Party Advisory", "VDB Entry"], "source": "psirt@adobe.com"}, {"url": "https://helpx.adobe.com/security/products/acrobat/apsb17-36.html", "tags": ["Vendor Advisory"], "source": "psirt@adobe.com"}, {"url": "http://www.securityfocus.com/bid/101831", "tags": ["Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securitytracker.com/id/1039791", "tags": ["Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://helpx.adobe.com/security/products/acrobat/apsb17-36.html", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-119"}]}], "descriptions": [{"lang": "en", "value": "An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value when processing TIFF files embedded within an XPS document. Crafted TIFF image input causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution."}, {"lang": "es", "value": "Se ha descubierto un problema en Adobe Acrobat y Reader: 2017.012.20098 y versiones anteriores, 2017.011.30066 y versiones anteriores, 2015.006.30355 y versiones anteriores y 11.0.22 y versiones anteriores. La vulnerabilidad se debe a un acceso al b\u00fafer con un valor de longitud incorrecto al procesar archivos TIFF embebidos en un documento XPS. La entrada de im\u00e1genes TIFF puede provocar una disparidad entre el tama\u00f1o de b\u00fafer asignado y el acceso permitido por el c\u00e1lculo. Si un atacante puede controlar adecuadamente la memoria accesible, esta vulnerabilidad puede ser aprovechada para lograr la ejecuci\u00f3n de c\u00f3digo arbitrario."}], "lastModified": "2025-04-20T01:37:25.860", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "43C26AAA-3620-4229-AEFC-78AB3B2AAACF", "versionEndIncluding": "11.0.22"}, {"criteria": "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2AD1E919-28D9-4C88-B8F9-95E062E9F9D0", "versionEndIncluding": "17.011.30066", "versionStartIncluding": "17.0"}, {"criteria": "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*", "vulnerable": true, "matchCriteriaId": "43E90FF1-8078-4B18-A492-507E6129D10D", "versionEndIncluding": "17.012.20098", "versionStartIncluding": "-"}, {"criteria": "cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:*", "vulnerable": true, "matchCriteriaId": "E45BE50E-04BE-49BE-8AFD-DFFAE6D11538", "versionEndIncluding": "15.006.30355", "versionStartIncluding": "15.0"}, {"criteria": "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA8E1E9D-FE27-4916-9BB3-D3E92BBB5641", "versionEndIncluding": "11.0.22"}, {"criteria": "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9346604B-ADB0-471B-9F81-8560E3F516AA", "versionEndIncluding": "17.011.30066", "versionStartIncluding": "17.0"}, {"criteria": "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*", "vulnerable": true, "matchCriteriaId": "2A50612A-DC1B-4F64-BF9F-748A15EC6610", "versionEndIncluding": "17.012.20098", "versionStartIncluding": "-"}, {"criteria": "cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:*", "vulnerable": true, "matchCriteriaId": "394E8F26-2B1C-47ED-85F9-32BC5E04EC3A", "versionEndIncluding": "15.006.30355", "versionStartIncluding": "15.0"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@adobe.com"}