RULE(RULE ID:316864)

Rule General Information
Release Date: 2019-04-02
Rule Name: Adobe Acrobat Imageconversion TIFF Heap-based Buffer Overflow Vulnerability (CVE-2017-2966)
Severity:
CVE ID:
Rule Protection Details
Description: Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the image conversion engine related to parsing malformed TIFF segments. Successful exploitation could lead to arbitrary code execution.
Impact: An attacker can execute arbitrary code in the context of the vulnerable system. Failed exploit may cause denial-of-service attack.
Affected OS: Windows
Reference: SecurityFocusBID:95344
AdobeSecurityBulletins:apsb17-01
SecurityTrackerID:1037574
ZeroDayInitiative:ZDI-17-030
Solutions
Adobe has issued a fix on the official website. For more advisory, please visit:
https://helpx.adobe.com/security/products/acrobat/apsb17-01.html