Skip to main content

Adobe Acrobat and Reader Multiple Code Execution Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 14 Apr 2010 4373 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Adobe Reader and Acrobat, which could be exploited by attackers to bypass security restrictions, gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system. These issues are caused by buffer overflows, memory corruptions, and inptu validation errors when processing malformed data within a PDF document, which could be exploited by attackers to inject malicious scripting code, disclose sensitive information or execute arbitrary code by tricking a user into opening a specially crafted PDF document.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Adobe Reader version 9.3.1 and prior
  • Adobe Reader version 8.2.1 and prior
  • Adobe Acrobat version 9.3.1 and prior
  • Adobe Acrobat version 8.2.1 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Upgrade to Adobe Acrobat and Reader version 9.3.2 or 8.2.2 :
http://www.adobe.com/support/security/bulletins/apsb10-09.html


Vulnerability Identifier


Source