HTTP: Adobe Reader Mobile JavaScript Interface Java Code Execution

This signature detects attempts to exploit a known vulnerability in the Adobe Mobile Reader for Android. A successful attack can lead to arbitrary code execution.

Extended Description

The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to execute arbitrary code via a crafted PDF document, a related issue to CVE-2012-6636.

Affected Products

Adobe adobe_reader

References

BugTraq: 66798

CVE: CVE-2014-0514

Short Name
HTTP:STC:ADOBE:READER-JAVA-CE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Adobe CVE-2014-0514 Code Execution Interface Java JavaScript Mobile Reader bid:66798
Release Date
05/05/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3398
False Positive
Unknown
Vendors

Adobe

CVSS Score

9.3

Found a potential security threat?