VDB
GSD-2009-1493
GSD-2009-1493
PUBLISHED
The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
Timeline
- Apr 28, 2009 CVE Published
- Apr 29, 2009 PoC Published
- Sep 23, 2014 PoC Published
- Jul 2, 2021 PoC Published
- Jan 24, 2023 PoC Published
- Jul 30, 2025 PoC Published
- Apr 16, 2026 Security Advisory
- Apr 16, 2026 Security Advisory
- Apr 16, 2026 Security Advisory
- Apr 16, 2026 Security Advisory
References
- http://blogs.adobe.com/psirt/2009/05/adobe_reader_issue_update.html url
- TA09-133B third-party-advisory
- ADV-2009-1189 vdb
- http://packetstorm.linuxsecurity.com/0904-exploits/spell.txt url
- 54129 vdb
- SUSE-SA:2009:027 vendor-advisory
- 34924 third-party-advisory
- 35055 third-party-advisory
- 35416 third-party-advisory
- RHSA-2009:0478 vendor-advisory
- 35152 third-party-advisory
- 34740 vdb
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=926953 url
- 35734 third-party-advisory
- reader-spellcustom-code-execution(50146) vdb
- http://www.adobe.com/support/security/bulletins/apsb09-06.html url
- SUSE-SR:2009:011 vendor-advisory
- http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html url
- 259028 vendor-advisory
- ADV-2009-1317 vdb
…and 6 more