Vulnerabilities > CVE-2013-3357 - Numeric Errors vulnerability in Adobe Acrobat and Acrobat Reader

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
adobe
apple
microsoft
CWE-189
critical
nessus

Summary

Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3358.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyWindows
    NASL idADOBE_ACROBAT_APSB13-22.NASL
    descriptionThe version of Adobe Acrobat installed on the remote host is earlier than 11.0.4 / 10.1.8. It is, therefore, affected by multiple vulnerabilities : - An unspecified stack overflow issue exists that could lead to code execution. (CVE-2013-3351) - Unspecified memory corruption vulnerabilities exist that could lead to code execution. (CVE-2013-3352, CVE-2013-3354, CVE-2013-3355) - Unspecified buffer overflow errors exist that could lead to code execution. (CVE-2013-3353, CVE-2013-3356) - Unspecified integer overflow errors exist that could lead to code execution. (CVE-2013-3357, CVE-2013-3358)
    last seen2020-06-01
    modified2020-06-02
    plugin id69845
    published2013-09-11
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/69845
    titleAdobe Acrobat < 11.0.4 / 10.1.8 Multiple Vulnerabilities (APSB13-22)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(69845);
      script_version("1.12");
      script_cvs_date("Date: 2019/11/27");
    
      script_cve_id(
        "CVE-2013-3351",
        "CVE-2013-3352",
        "CVE-2013-3353",
        "CVE-2013-3354",
        "CVE-2013-3355",
        "CVE-2013-3356",
        "CVE-2013-3357",
        "CVE-2013-3358"
      );
      script_bugtraq_id(
        62428,
        62429,
        62430,
        62431,
        62432,
        62433,
        62435,
        62436
      );
    
      script_name(english:"Adobe Acrobat < 11.0.4 / 10.1.8 Multiple Vulnerabilities (APSB13-22)");
      script_summary(english:"Checks version of Adobe Acrobat");
    
      script_set_attribute(attribute:"synopsis", value:
    "The version of Adobe Acrobat on the remote Windows host is affected by
    multiple vulnerabilities.");
      script_set_attribute(attribute:"description", value:
    "The version of Adobe Acrobat installed on the remote host is earlier
    than 11.0.4 / 10.1.8.  It is, therefore, affected by multiple
    vulnerabilities :
    
      - An unspecified stack overflow issue exists that could
        lead to code execution. (CVE-2013-3351)
    
      - Unspecified memory corruption vulnerabilities exist that
        could lead to code execution. (CVE-2013-3352,
        CVE-2013-3354, CVE-2013-3355)
    
      - Unspecified buffer overflow errors exist that could
        lead to code execution. (CVE-2013-3353, CVE-2013-3356)
    
      - Unspecified integer overflow errors exist that could
        lead to code execution. (CVE-2013-3357, CVE-2013-3358)");
      script_set_attribute(attribute:"see_also", value:"http://www.zerodayinitiative.com/advisories/ZDI-13-230/");
      script_set_attribute(attribute:"see_also", value:"http://www.adobe.com/support/security/bulletins/apsb13-22.html");
      script_set_attribute(attribute:"solution", value:
    "Upgrade to Adobe Acrobat 11.0.4 / 10.1.8 or later.");
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C");
      script_set_cvss_temporal_vector("CVSS2#E:H/RL:OF/RC:C");
      script_set_attribute(attribute:"cvss_score_source", value:"CVE-2013-3358");
    
      script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available");
      script_set_attribute(attribute:"exploit_available", value:"true");
      script_set_attribute(attribute:"exploited_by_malware", value:"true");
    
      script_set_attribute(attribute:"vuln_publication_date", value:"2013/09/10");
      script_set_attribute(attribute:"patch_publication_date", value:"2013/09/10");
      script_set_attribute(attribute:"plugin_publication_date", value:"2013/09/11");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"cpe:/a:adobe:acrobat");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_family(english:"Windows");
    
      script_copyright(english:"This script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.");
    
      script_dependencies("adobe_acrobat_installed.nasl");
      script_require_keys("SMB/Acrobat/Version");
    
      exit(0);
    }
    
    include('audit.inc');
    include('global_settings.inc');
    include('misc_func.inc');
    
    version = get_kb_item_or_exit("SMB/Acrobat/Version");
    version_ui = get_kb_item('SMB/Acrobat/Version_UI');
    
    if (isnull(version_ui)) version_report = version;
    else version_report = version_ui;
    
    ver = split(version, sep:'.', keep:FALSE);
    for (i=0; i<max_index(ver); i++)
      ver[i] = int(ver[i]);
    
    path = get_kb_item_or_exit('SMB/Acrobat/Path');
    
    if (
      (ver[0] == 10 && ver[1] < 1) ||
      (ver[0] == 10 && ver[1] == 1 && ver[2] < 8) ||
      (ver[0] == 11 && ver[1] == 0 && ver[2] < 4)
    )
    {
      port = get_kb_item('SMB/transport');
      if (!port) port = 445;
    
      if (report_verbosity > 0)
      {
        report =
          '\n  Path              : '+path+
          '\n  Installed version : '+version_report+
          '\n  Fixed version     : 11.0.4 / 10.1.8\n';
        security_hole(port:port, extra:report);
      }
      else security_hole(port);
    }
    else audit(AUDIT_INST_PATH_NOT_VULN, "Adobe Acrobat", version_report, path);
    
  • NASL familyWindows
    NASL idADOBE_READER_APSB13-22.NASL
    descriptionThe version of Adobe Reader installed on the remote host is earlier than 11.0.4 / 10.1.8. It is, therefore, affected by multiple vulnerabilities : - An unspecified stack overflow issue exists that could lead to code execution. (CVE-2013-3351) - Unspecified memory corruption vulnerabilities exist that could lead to code execution. (CVE-2013-3352, CVE-2013-3354, CVE-2013-3355) - Unspecified buffer overflow errors exist that could lead to code execution. (CVE-2013-3353, CVE-2013-3356) - Unspecified integer overflow errors exist that could lead to code execution. (CVE-2013-3357, CVE-2013-3358)
    last seen2020-06-01
    modified2020-06-02
    plugin id69846
    published2013-09-11
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/69846
    titleAdobe Reader < 11.0.4 / 10.1.8 Multiple Vulnerabilities (APSB13-22)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(69846);
      script_version("1.12");
      script_cvs_date("Date: 2019/11/27");
    
      script_cve_id(
        "CVE-2013-3351",
        "CVE-2013-3352",
        "CVE-2013-3353",
        "CVE-2013-3354",
        "CVE-2013-3355",
        "CVE-2013-3356",
        "CVE-2013-3357",
        "CVE-2013-3358"
      );
      script_bugtraq_id(
        62428,
        62429,
        62430,
        62431,
        62432,
        62433,
        62435,
        62436
      );
    
      script_name(english:"Adobe Reader < 11.0.4 / 10.1.8 Multiple Vulnerabilities (APSB13-22)");
      script_summary(english:"Checks version of Adobe Reader");
    
      script_set_attribute(attribute:"synopsis", value:
    "The version of Adobe Reader on the remote Windows host is affected by
    multiple vulnerabilities.");
      script_set_attribute(attribute:"description", value:
    "The version of Adobe Reader installed on the remote host is earlier
    than 11.0.4 / 10.1.8.  It is, therefore, affected by multiple
    vulnerabilities :
    
      - An unspecified stack overflow issue exists that could
        lead to code execution. (CVE-2013-3351)
    
      - Unspecified memory corruption vulnerabilities exist that
        could lead to code execution. (CVE-2013-3352,
        CVE-2013-3354, CVE-2013-3355)
    
      - Unspecified buffer overflow errors exist that could
        lead to code execution. (CVE-2013-3353, CVE-2013-3356)
    
      - Unspecified integer overflow errors exist that could
        lead to code execution. (CVE-2013-3357, CVE-2013-3358)");
      script_set_attribute(attribute:"see_also", value:"http://www.zerodayinitiative.com/advisories/ZDI-13-230/");
      script_set_attribute(attribute:"see_also", value:"http://www.adobe.com/support/security/bulletins/apsb13-22.html");
      script_set_attribute(attribute:"solution", value:
    "Upgrade to Adobe Reader 11.0.4 / 10.1.8 or later.");
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C");
      script_set_cvss_temporal_vector("CVSS2#E:H/RL:OF/RC:C");
      script_set_attribute(attribute:"cvss_score_source", value:"CVE-2013-3358");
    
      script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available");
      script_set_attribute(attribute:"exploit_available", value:"true");
      script_set_attribute(attribute:"exploited_by_malware", value:"true");
    
      script_set_attribute(attribute:"vuln_publication_date", value:"2013/09/10");
      script_set_attribute(attribute:"patch_publication_date", value:"2013/09/10");
      script_set_attribute(attribute:"plugin_publication_date", value:"2013/09/11");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"cpe:/a:adobe:acrobat_reader");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_family(english:"Windows");
    
      script_copyright(english:"This script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.");
    
      script_dependencies("adobe_reader_installed.nasl");
      script_require_keys("SMB/Acroread/Version");
    
      exit(0);
    }
    
    include('audit.inc');
    include('global_settings.inc');
    
    info =  '';
    info2 = '';
    vuln = 0;
    vers = get_kb_list('SMB/Acroread/Version');
    if (isnull(vers)) audit(AUDIT_KB_MISSING, 'SMB/Acroread/Version');
    
    foreach version (vers)
    {
      ver = split(version, sep:'.', keep:FALSE);
      for (i=0; i<max_index(ver); i++)
        ver[i] = int(ver[i]);
    
      path = get_kb_item('SMB/Acroread/'+version+'/Path');
      if (isnull(path)) path = 'n/a';
    
      verui = get_kb_item('SMB/Acroread/'+version+'/Version_UI');
      if (isnull(verui)) verui = version;
    
      if (
        (ver[0] == 10 && ver[1] < 1) ||
        (ver[0] == 10 && ver[1] == 1 && ver[2] < 8) ||
        (ver[0] == 11 && ver[1] == 0 && ver[2] < 4)
      )
      {
        vuln++;
        info += '\n  Path              : '+path+
                '\n  Installed version : '+verui+
                '\n  Fixed version     : 11.0.4 / 10.1.8\n';
      }
      else
        info2 += " and " + verui;
    }
    
    if (info)
    {
      port = get_kb_item("SMB/transport");
      if (!port) port = 445;
    
      if (report_verbosity > 0)
      {
        if (vuln > 1) s = "s of Adobe Reader are";
        else s = " of Adobe Reader is";
    
        report =
          '\nThe following vulnerable instance'+s+' installed on the'+
          '\nremote host :\n'+
          info;
        security_hole(port:port, extra:report);
      }
      else security_hole(port);
    
      exit(0);
    }
    
    if (info2)
    {
      info2 -= " and ";
      if (" and " >< info2) be = "are";
      else be = "is";
    
      exit(0, "The host is not affected since Adobe Reader "+info2+" "+be+" installed.");
    }
    else exit(1, "Unexpected error - 'info2' is empty.");
    
  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_ADOBE_READER_APSB13-22.NASL
    descriptionThe version of Adobe Reader installed on the remote Mac OS X host is prior to 11.0.4 or 10.1.8. It is, therefore, affected by the following vulnerabilities : - Multiple unspecified stack overflow conditions exist that allow an attacker to execute arbitrary code. (CVE-2013-3351) - Multiple unspecified memory corruption issues exist that allow an attacker to execute arbitrary code. (CVE-2013-3352, CVE-2013-3354, CVE-2013-3355) - Multiple unspecified buffer overflow conditions exist that allow an attacker to execute arbitrary code. (CVE-2013-3353, CVE-2013-3356) - Multiple unspecified integer overflow conditions exist that allow an attacker to execute arbitrary code. (CVE-2013-3357, CVE-2013-3358) Note that Nessus has not tested for these issues but has instead relied only on the application
    last seen2020-06-01
    modified2020-06-02
    plugin id69847
    published2013-09-11
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/69847
    titleAdobe Reader < 11.0.4 / 10.1.8 Multiple Vulnerabilities (APSB13-22) (Mac OS X)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(69847);
      script_version("1.13");
      script_cvs_date("Date: 2019/11/27");
    
      script_cve_id(
        "CVE-2013-3351",
        "CVE-2013-3352",
        "CVE-2013-3353",
        "CVE-2013-3354",
        "CVE-2013-3355",
        "CVE-2013-3356",
        "CVE-2013-3357",
        "CVE-2013-3358"
      );
      script_bugtraq_id(
        62428,
        62429,
        62430,
        62431,
        62432,
        62433,
        62435,
        62436
      );
      script_xref(name:"ZDI", value:"ZDI-13-230");
    
      script_name(english:"Adobe Reader < 11.0.4 / 10.1.8 Multiple Vulnerabilities (APSB13-22) (Mac OS X)");
      script_summary(english:"Checks the version of Adobe Reader.");
    
      script_set_attribute(attribute:"synopsis", value:
    "The version of Adobe Reader on the remote Mac OS X host is affected by
    multiple vulnerabilities.");
      script_set_attribute(attribute:"description", value:
    "The version of Adobe Reader installed on the remote Mac OS X host is
    prior to 11.0.4 or 10.1.8. It is, therefore, affected by the following
    vulnerabilities :
    
      - Multiple unspecified stack overflow conditions exist
        that allow an attacker to execute arbitrary code.
        (CVE-2013-3351)
    
      - Multiple unspecified memory corruption issues exist that
        allow an attacker to execute arbitrary code.
        (CVE-2013-3352, CVE-2013-3354, CVE-2013-3355)
    
      - Multiple unspecified buffer overflow conditions exist
        that allow an attacker to execute arbitrary code.
        (CVE-2013-3353, CVE-2013-3356)
    
      - Multiple unspecified integer overflow conditions exist
        that allow an attacker to execute arbitrary code.
        (CVE-2013-3357, CVE-2013-3358)
    
    Note that Nessus has not tested for these issues but has instead
    relied only on the application's self-reported version number.");
      script_set_attribute(attribute:"see_also", value:"http://www.zerodayinitiative.com/advisories/ZDI-13-230/");
      script_set_attribute(attribute:"see_also", value:"http://www.adobe.com/support/security/bulletins/apsb13-22.html");
      script_set_attribute(attribute:"solution", value:
    "Upgrade to Adobe Reader version 11.0.4 / 10.1.8 or later.");
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C");
      script_set_cvss_temporal_vector("CVSS2#E:H/RL:OF/RC:C");
      script_set_attribute(attribute:"cvss_score_source", value:"CVE-2013-3358");
    
      script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available");
      script_set_attribute(attribute:"exploit_available", value:"true");
      script_set_attribute(attribute:"exploited_by_malware", value:"true");
    
      script_set_attribute(attribute:"vuln_publication_date", value:"2013/09/10");
      script_set_attribute(attribute:"patch_publication_date", value:"2013/09/10");
      script_set_attribute(attribute:"plugin_publication_date", value:"2013/09/11");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"cpe:/a:adobe:acrobat_reader");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_family(english:"MacOS X Local Security Checks");
    
      script_copyright(english:"This script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.");
    
      script_dependencies("macosx_adobe_reader_installed.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/MacOSX/Version", "installed_sw/Adobe Reader");
    
      exit(0);
    }
    
    include("audit.inc");
    include("global_settings.inc");
    include("install_func.inc");
    include("misc_func.inc");
    
    if (!get_kb_item("Host/local_checks_enabled"))
      audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
    
    if (!get_kb_item("Host/MacOSX/Version"))
      audit(AUDIT_OS_NOT, "Mac OS X");
    
    app = "Adobe Reader";
    install = get_single_install(app_name:app, exit_if_unknown_ver:TRUE);
    version = install['version'];
    path = install['path'];
    
    ver = split(version, sep:".", keep:FALSE);
    for (i=0; i<max_index(ver); i++)
      ver[i] = int(ver[i]);
    
    if (
      (ver[0] == 10 && ver[1] < 1) ||
      (ver[0] == 10 && ver[1] == 1 && ver[2] < 8)
    )
      fix = "10.1.8";
    else if (ver[0] == 11 && ver[1] == 0 && ver[2] < 4)
      fix = "11.0.4";
    else
      fix = "";
    
    if (fix)
    {
      info =
        '\n  Path              : ' + path +
        '\n  Installed version : ' + version +
        '\n  Fixed version     : ' + fix +
        '\n';
      security_report_v4(port:0, extra:info, severity:SECURITY_HOLE);
    }
    else
      audit(AUDIT_INST_PATH_NOT_VULN, app, version, path);
    

Oval

accepted2013-11-26T13:49:25.095-05:00
classvulnerability
contributors
nameShane Shaffer
organizationG2, Inc.
definition_extensions
  • commentAdobe Reader 10.x is installed
    ovaloval:org.mitre.oval:def:12283
  • commentAdobe Reader 11.x is installed
    ovaloval:org.mitre.oval:def:16400
  • commentAdobe Acrobat 10.x is installed
    ovaloval:org.mitre.oval:def:11989
  • commentAdobe Acrobat 11.x is installed
    ovaloval:org.mitre.oval:def:16409
descriptionInteger overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3358.
familywindows
idoval:org.mitre.oval:def:19064
statusaccepted
submitted2013-10-16T15:34:02.324-04:00
titleInteger overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3358
version4