==================================================================== CERT-Renater Note d'Information No. 2016/VULN204 _____________________________________________________________________ DATE : 11/05/2016 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Adobe Acrobat, Adobe Reader versions prior to 15.016.20039, 15.006.30172, 11.0.16. ====================================================================== https://helpx.adobe.com/security/products/acrobat/apsb16-14.html ____________________________________________________________________ Adobe Security Bulletin Security Updates Available for Adobe Acrobat and Reader Release date: May 5, 2016 Last Updated: May 10,2016 Vulnerability identifier: APSB16-14 Priority: 2 CVE Numbers: CVE-2016-1037, CVE-2016-1038, CVE-2016-1039, CVE-2016-1040, CVE-2016-1041, CVE-2016-1042, CVE-2016-1043, CVE-2016-1044, CVE-2016-1045, CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1051, CVE-2016-1052, CVE-2016-1053, CVE-2016-1054, CVE-2016-1055, CVE-2016-1056, CVE-2016-1057, CVE-2016-1058, CVE-2016-1059, CVE-2016-1060, CVE-2016-1061, CVE-2016-1062, CVE-2016-1063, CVE-2016-1064, CVE-2016-1065, CVE-2016-1066, CVE-2016-1067, CVE-2016-1068, CVE-2016-1069, CVE-2016-1070, CVE-2016-1071, CVE-2016-1072, CVE-2016-1073, CVE-2016-1074, CVE-2016-1075, CVE-2016-1076, CVE-2016-1077, CVE-2016-1078, CVE-2016-1079, CVE-2016-1080, CVE-2016-1081, CVE-2016-1082, CVE-2016-1083, CVE-2016-1084, CVE-2016-1085, CVE-2016-1086, CVE-2016-1087, CVE-2016-1088, CVE-2016-1090, CVE-2016-1092, CVE-2016-1093, CVE-2016-1094, CVE-2016-1095, CVE-2016-1112, CVE-2016-1116, CVE-2016-1117, CVE-2016-1118, CVE-2016-1119, CVE-2016-1120, CVE-2016-1121, CVE-2016-1122, CVE-2016-1123, CVE-2016-1124, CVE-2016-1125, CVE-2016-1126, CVE-2016-1127, CVE-2016-1128, CVE-2016-1129, CVE-2016-1130, CVE-2016-4088, CVE-2016-4089, CVE-2016-4090, CVE-2016-4091, CVE-2016-4092, CVE-2016-4093, CVE-2016-4094, CVE-2016-4096, CVE-2016-4097, CVE-2016-4098, CVE-2016-4099, CVE-2016-4100, CVE-2016-4101, CVE-2016-4102, CVE-2016-4103, CVE-2016-4104, CVE-2016-4105, CVE-2016-4106, CVE-2016-4107 Platform: Windows and Macintosh Summary Adobe has released security updates for Adobe Acrobat and Reader for Windows and Macintosh. These updates address critical vulnerabilities that could potentially allow an attacker to take control of the affected system. Affected Versions Product Track Affected Versions Platform Acrobat DC Continuous 15.010.20060 and earlier versions Windows and Macintosh Acrobat Reader DC Continuous 15.010.20060 and earlier versions Windows and Macintosh Acrobat DC Classic 15.006.30121 and earlier versions Windows and Macintosh Acrobat Reader DC Classic 15.006.30121 and earlier versions Windows and Macintosh Acrobat XI Desktop 11.0.15 and earlier versions Windows and Macintosh Reader XI Desktop 11.0.15 and earlier versions Windows and Macintosh For questions regarding Acrobat DC, please visit the Acrobat DC FAQ page. For questions regarding Acrobat Reader DC, please visit the Acrobat Reader DC FAQ page. Solution Adobe recommends users update their software installations to the latest versions by following the instructions below. The latest product versions are available to end users via one of the following methods: Users can update their product installations manually by choosing Help > Check for Updates. The products will update automatically, without requiring user intervention, when updates are detected. The full Acrobat Reader installer can be downloaded from the Acrobat, Reader Download Center. For IT administrators (managed environments): Download the enterprise installers from ftp://ftp.adobe.com/pub/adobe/, or refer to the specific release note version for links to installers. Install updates via your preferred methodology, such as AIP-GPO, bootstrapper, SCUP/SCCM (Windows), or on Macintosh, Apple Remote Desktop and SSH. Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version: Product Track Affected Versions Platform Priority Rating Availability Acrobat DC Continuous 15.016.20039 Windows and Macintosh 2 Windows Macintosh Acrobat Reader DC Continuous 15.016.20039 Windows and Macintosh 2 Download Center Acrobat DC Classic 15.006.30172 Windows and Macintosh 2 Windows Macintos Acrobat Reader DC Classic 15.006.30172 Windows and Macintosh 2 Windows Macintosh Acrobat XI Desktop 11.0.16 Windows and Macintosh 2 Windows Macintosh Reader XI Desktop 11.0.16 Windows and Macintosh 2 Windows Macintosh Vulnerability Details These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2016-1045, CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1051, CVE-2016-1052, CVE-2016-1053, CVE-2016-1054, CVE-2016-1055, CVE-2016-1056, CVE-2016-1057, CVE-2016-1058, CVE-2016-1059, CVE-2016-1060, CVE-2016-1061, CVE-2016-1065, CVE-2016-1066, CVE-2016-1067, CVE-2016-1068, CVE-2016-1069, CVE-2016-1070, CVE-2016-1075, CVE-2016-1094, CVE-2016-1121, CVE-2016-1122, CVE-2016-4102, CVE-2016-4107). These updates resolve heap buffer overflow vulnerabilities that could lead to code execution (CVE-2016-4091, CVE-2016-4092). These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2016-1037, CVE-2016-1063, CVE-2016-1064, CVE-2016-1071, CVE-2016-1072, CVE-2016-1073, CVE-2016-1074, CVE-2016-1076, CVE-2016-1077, CVE-2016-1078, CVE-2016-1080, CVE-2016-1081, CVE-2016-1082, CVE-2016-1083, CVE-2016-1084, CVE-2016-1085, CVE-2016-1086, CVE-2016-1088, CVE-2016-1093, CVE-2016-1095, CVE-2016-1116, CVE-2016-1118, CVE-2016-1119, CVE-2016-1120, CVE-2016-1123, CVE-2016-1124, CVE-2016-1125, CVE-2016-1126, CVE-2016-1127, CVE-2016-1128, CVE-2016-1129, CVE-2016-1130, CVE-2016-4088, CVE-2016-4089, CVE-2016-4090, CVE-2016-4093, CVE-2016-4094, CVE-2016-4096, CVE-2016-4097, CVE-2016-4098, CVE-2016-4099, CVE-2016-4100, CVE-2016-4101, CVE-2016-4103, CVE-2016-4104, CVE-2016-4105). These updates resolve an integer overflow vulnerability that could lead to code execution (CVE-2016-1043). These updates resolve memory leak vulnerabilities (CVE-2016-1079, CVE-2016-1092). These updates resolve an information disclosure issue (CVE-2016-1112). These updates resolve various methods to bypass restrictions on Javascript API execution (CVE-2016-1038, CVE-2016-1039, CVE-2016-1040, CVE-2016-1041, CVE-2016-1042, CVE-2016-1044, CVE-2016-1062, CVE-2016-1117). These updates resolve vulnerabilities in the directory search path used to find resources that could lead to code execution (CVE-2016-1087, CVE-2016-1090, CVE-2016-4106). Acknowledgements Adobe would like to thank the following individuals and organizations for reporting the relevant issues and for working with Adobe to help protect our customers: Jaanus Kaap of Clarified Security (CVE-2016-1088, CVE-2016-1093)\ Brian Gorenc working with Trend Micro's Zero Day Initiative (CVE-2016-1065) AbdulAziz Hariri working with Trend Micro's Zero Day Initiative (CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1051, CVE-2016-1052, CVE-2016-1053, CVE-2016-1054, CVE-2016-1055, CVE-2016-1056, CVE-2016-1057, CVE-2016-1058, CVE-2016-1059, CVE-2016-1060, CVE-2016-1061, CVE-2016-1062, CVE-2016-1066, CVE-2016-1067, CVE-2016-1068, CVE-2016-1069, CVE-2016-1070, CVE-2016-1076, CVE-2016-1079, CVE-2016-1117) AbdulAziz Hariri and Jasiel Spelman working with Trend Micro's Zero Day Initiative (CVE-2016-1080) Eric Lawrence (CVE-2016-1090) Ke Liu of Tencent's Xuanwu LAB (CVE-2016-1118, CVE-2016-1119, CVE-2016-1120, CVE-2016-1121, CVE-2016-1122, CVE-2016-1123, CVE-2016-1124, CVE-2016-1125, CVE-2016-1126, CVE-2016-1127, CVE-2016-1128, CVE-2016-1129, CVE-2016-1130, CVE-2016-4088, CVE-2016-4089, CVE-2016-4090, CVE-2016-4091, CVE-2016-4092, CVE-2016-4093, CVE-2016-4094, CVE-2016-4096, CVE-2016-4097, CVE-2016-4098, CVE-2016-4099, CVE-2016-4100, CVE-2016-4101, CVE-2016-4102, CVE-2016-4103, CVE-2016-4104, CVE-2016-4105, CVE-2016-4106, CVE-2016-4107) kdot working with Trend Micro's Zero Day Initiative (CVE-2016-1063, CVE-2016-1071, CVE-2016-1074, CVE-2016-1075, CVE-2016-1078, CVE-2016-1095) Anand Bhat (CVE-2016-1087) Sebastian Apelt of Siberas (CVE-2016-1092) Wei Lei and Liu Yang of Nanyang Technological University (CVE-2016-1116) Pier-Luc Maltais of COSIG (CVE-2016-1077) Matthias Kaiser working with Trend Micro's Zero Day Initiative (CVE-2016-1038, CVE-2016-1039, CVE-2016-1040, CVE-2016-1041, CVE-2016-1042, CVE-2016-1044) Jaanus Kp Clarified Security working with Trend Micro's Zero Day Initiative (CVE-2016-1094) Sebastian Apelt siberas working with Trend Micro's Zero Day Initiative (CVE-2016-1072, CVE-2016-1073) Anonymous working with Trend Micro's Zero Day Initiative (CVE-2016-1043, CVE-2016-1045) kelvinwang of Tencent PC Manager (CVE-2016-1081, CVE-2016-1082, CVE-2016-1083, CVE-2016-1084, CVE-2016-1085, CVE-2016-1086) Wei Lei, Wu Hongjun and Liu Yang working with iDefense Vulnerability Contributor Program (CVE-2016-1037) Alex Infuhr of Cure53.de (CVE-2016-1064) ========================================================== Serveur de référence du CERT-Renater https://services.renater.fr/ssi/ ========================================================== + CERT-RENATER | tel : 01-53-94-20-44 + + 23 - 25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email: cert@support.renater.fr + ==========================================================