Adobe Acrobat and Reader Multiple Code Execution Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Adobe Reader and Acrobat, which could be exploited by attackers to bypass security restrictions, gain knowledge of sensitive information, cause a denial of service or compromise a vulnerable system. These issues are caused by buffer overflows, memory corruptions, and inptu validation errors when processing malformed data within a PDF document, which could be exploited by attackers to inject malicious scripting code, disclose sensitive information or execute arbitrary code by tricking a user into opening a specially crafted PDF document.
Impact
- Denial of Service
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- Adobe Reader version 9.3.1 and prior
- Adobe Reader version 8.2.1 and prior
- Adobe Acrobat version 9.3.1 and prior
- Adobe Acrobat version 8.2.1 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Upgrade to Adobe Acrobat and Reader version 9.3.2 or 8.2.2 :
http://www.adobe.com/support/security/bulletins/apsb10-09.html
Vulnerability Identifier
- CVE-2010-0190
- CVE-2010-0191
- CVE-2010-0192
- CVE-2010-0193
- CVE-2010-0194
- CVE-2010-0195
- CVE-2010-0196
- CVE-2010-0197
- CVE-2010-0198
- CVE-2010-0199
- CVE-2010-0201
- CVE-2010-0202
- CVE-2010-0203
- CVE-2010-0204
- CVE-2010-1241
Source
Share with