A JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to obtain sensitive information via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.adobe.com/support/security/bulletins/apsb13-15.html | patch vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00004.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-0826.html | vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16864 | signature vdb entry |
http://security.gentoo.org/glsa/glsa-201308-03.xml | vendor advisory |