Skip to main content

Adobe Acrobat / Reader SING Font Buffer Overflow Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 9 Sep 2010 4451 Views

RISK: Medium Risk

A vulnerability has been identified in Adobe Acrobat and Reader, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error in the "CoolType.dll" module when processing a PDF document containing malformed SING (Smart INdependent Glyphlets) fonts, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into opening a specially crafted PDF document.

This vulnerability is exploited in the wild.


Impact

  • Remote Code Execution

System / Technologies affected

  • Adobe Reader version 9.3.4 and prior
  • Adobe Acrobat version 9.3.4 and prior

Solutions

Please refer to "Adobe Acrobat and Reader Multiple Vulnerabilities".


Vulnerability Identifier


Source


Related Link