openSUSE Security Update : acroread (acroread-1849)

critical Nessus Plugin ID 44126



The remote openSUSE host is missing a security update.


Specially crafted PDF files could crash acroread. Attackers could exploit that to potentially execute arbitrary code (CVE-2009-3953, CVE-2009-3954, CVE-2009-3955, CVE-2009-3956, CVE-2009-3957, CVE-2009-3958, CVE-2009-3959, CVE-2009-4324).

Acrobat reader was updated to version 9.3 to fix those security issues.


Update the affected acroread package.

See Also

Plugin Details

Severity: Critical

ID: 44126

File Name: suse_11_1_acroread-100122.nasl

Version: 1.15

Type: local

Agent: unix

Published: 1/25/2010

Updated: 6/8/2022

Supported Sensors: Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information


Risk Factor: Critical

Score: 9.5


Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:acroread, cpe:/o:novell:opensuse:11.1

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/22/2010

CISA Known Exploited Vulnerability Due Dates: 6/22/2022

Exploitable With


Core Impact

Metasploit (Adobe Use After Free Vulnerability)

Reference Information

CVE: CVE-2009-3953, CVE-2009-3954, CVE-2009-3955, CVE-2009-3956, CVE-2009-3957, CVE-2009-3958, CVE-2009-3959, CVE-2009-4324

CWE: 119, 16, 189, 399, 94