CVE-2013-0641
adobe acrobat, adobe acrobat reader, redhat enterprise linux desktop
Published 14 Feb 2013 · updated 16 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Mar 2022, with a remediation deadline of 24 Mar 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February 2013.
References
- blog.fireeye.com/research/2013/02/in-turn-its-pdf-time.html · Broken Link
- blogs.adobe.com/psirt/2013/02/adobe-reader-and-acrobat-vulnerability-report.html · Broken Link, Vendor Advisory
- blogs.mcafee.com/mcafee-labs/digging-into-the-sandbox-escape-technique-of-the-recent-pdf-exploit · Broken Link
- lists.opensuse.org/opensuse-security-announce/2013-02/msg00021.html · Mailing List, Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2013-02/msg00023.html · Mailing List, Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2013-02/msg00024.html · Mailing List, Third Party Advisory
- rhn.redhat.com/errata/RHSA-2013-0551.html · Third Party Advisory
- security.gentoo.org/glsa/glsa-201308-03.xml · Third Party Advisory
- www.adobe.com/support/security/advisories/apsa13-02.html · Vendor Advisory
- www.adobe.com/support/security/bulletins/apsb13-07.html · Broken Link
- www.kb.cert.org/vuls/id/422807 · Third Party Advisory, US Government Resource
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16296 · Broken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0641 · US Government Resource