CVE-2012-4896
critical
CVSS v3
—
CVSS v2
9.3
VIR risk
9.3
Description
Heap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2012-4895.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| sumatrapdfreader | sumatrapdf | {"endIncluding":"2.0.1"} | |
| sumatrapdfreader | sumatrapdf | 0.1 | |
| sumatrapdfreader | sumatrapdf | 0.2 | |
| sumatrapdfreader | sumatrapdf | 0.3 | |
| sumatrapdfreader | sumatrapdf | 0.4 | |
| sumatrapdfreader | sumatrapdf | 0.5 | |
| sumatrapdfreader | sumatrapdf | 0.6 | |
| sumatrapdfreader | sumatrapdf | 0.7 | |
| sumatrapdfreader | sumatrapdf | 0.8 | |
| sumatrapdfreader | sumatrapdf | 0.8.1 | |
| sumatrapdfreader | sumatrapdf | 0.9 | |
| sumatrapdfreader | sumatrapdf | 0.9.1 | |
| sumatrapdfreader | sumatrapdf | 0.9.2 | |
| sumatrapdfreader | sumatrapdf | 0.9.3 | |
| sumatrapdfreader | sumatrapdf | 0.9.4 | |
| sumatrapdfreader | sumatrapdf | 1.0 | |
| sumatrapdfreader | sumatrapdf | 1.0.1 | |
| sumatrapdfreader | sumatrapdf | 1.1 | |
| sumatrapdfreader | sumatrapdf | 1.2 | |
| sumatrapdfreader | sumatrapdf | 1.3 | |
| sumatrapdfreader | sumatrapdf | 1.4 | |
| sumatrapdfreader | sumatrapdf | 1.5 | |
| sumatrapdfreader | sumatrapdf | 1.5.1 | |
| sumatrapdfreader | sumatrapdf | 1.6 | |
| sumatrapdfreader | sumatrapdf | 1.7 | |
| sumatrapdfreader | sumatrapdf | 1.8 | |
| sumatrapdfreader | sumatrapdf | 1.9 | |
| sumatrapdfreader | sumatrapdf | 2.0 | |
References
- http://code.google.com/p/sumatrapdf/source/browse/trunk/docs/releasenotes.txt
- http://secunia.com/advisories/50656
- http://technet.microsoft.com/security/msvr/msvr12-014
- http://code.google.com/p/sumatrapdf/source/browse/trunk/docs/releasenotes.txt
- http://secunia.com/advisories/50656
- http://technet.microsoft.com/security/msvr/msvr12-014
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.