Back to search
CVE-2008-2992
Published: Nov 4, 2008
Modified: Oct 22, 2025
PUBLISHED
Description
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
30035
vdb-entry
x_refsource_BID
32700
third-party-advisory
x_refsource_SECUNIA
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=909609
x_refsource_CONFIRM
20081104 Secunia Research: Adobe Acrobat/Reader "util.printf()" Buffer Overflow
mailing-list
x_refsource_BUGTRAQ
http://secunia.com/secunia_research/2008-14/
x_refsource_MISC
32091
vdb-entry
x_refsource_BID
49520
vdb-entry
x_refsource_OSVDB
35163
third-party-advisory
x_refsource_SECUNIA
249366
vendor-advisory
x_refsource_SUNALERT
32872
third-party-advisory
x_refsource_SECUNIA
7006
exploit
x_refsource_EXPLOIT-DB
4549
third-party-advisory
x_refsource_SREASON
http://www.coresecurity.com/content/adobe-reader-buffer-overflow
x_refsource_MISC
http://www.zerodayinitiative.com/advisories/ZDI-08-072/
x_refsource_MISC
http://www.adobe.com/support/security/bulletins/apsb08-19.html
x_refsource_CONFIRM
20081104 ZDI-08-072: Adobe Acrobat PDF Javascript printf Stack Overflow Vulnerability
mailing-list
x_refsource_BUGTRAQ
6994
exploit
x_refsource_EXPLOIT-DB
ADV-2009-0098
vdb-entry
x_refsource_VUPEN
29773
third-party-advisory
x_refsource_SECUNIA
TA08-309A
third-party-advisory
x_refsource_CERT
1021140
vdb-entry
x_refsource_SECTRACK
20081104 CORE-2008-0526: Adobe Reader Javascript Printf Buffer Overflow
mailing-list
x_refsource_BUGTRAQ
ADV-2008-3001
vdb-entry
x_refsource_VUPEN
SUSE-SR:2008:026
vendor-advisory
x_refsource_SUSE
RHSA-2008:0974
vendor-advisory
x_refsource_REDHAT
VU#593409
third-party-advisory
x_refsource_CERT-VN
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=800801
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now