Skip to main content

Adobe Acrobat and Reader "printSeps()" Heap Corruption Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 5 Nov 2010 4875 Views

RISK: Medium Risk

A vulnerability has been identified in Adobe Acrobat and Reader, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a heap corruption error in the "EScript.api" plugin when processing the "printSeps()" function within a PDF document, which could be exploited by attackers to crash an affected application or potentially compromise a vulnerable system by tricking a user into opening a specially crafted PDF file.


Impact

  • Remote Code Execution

System / Technologies affected

  • Adobe Reader version 9.4 and prior
  • Adobe Reader version 8.2.5 and prior
  • Adobe Acrobat version 9.4 and prior
  • Adobe Acrobat version 8.2.5 and prior

Solutions

  • There is no patch available for this vulnerability currently.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link