HIGH KEV
acroread: media.newplayer JavaScript API code execution vulnerability (APSB10-02)
Published Dec 15, 2009 ·Due Jun 22, 2022
7.8
HIGHCVSS 3.1
EPSS 81.88%
Description
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.
Affected products
No data.
Configuration 1
Configuration 2
OR
- 11
- 11.1
- 11.2
- 10.0
- 10.0
No data.
Extras for RHEL 3
acroread-0:9.3-3
Fixed · RHSA-2010:0060
Extras for RHEL 4
acroread-0:9.3-1.el4
Fixed · RHSA-2010:0038
Supplementary for Red Hat Enterprise Linux 5
acroread-0:9.3-1.el5
Fixed · RHSA-2010:0037
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 3 | acroread-0:9.3-3 | Fixed | RHSA-2010:0060 |
| Extras for RHEL 4 | acroread-0:9.3-1.el4 | Fixed | RHSA-2010:0038 |
| Supplementary for Red Hat Enterprise Linux 5 | acroread-0:9.3-1.el5 | Fixed | RHSA-2010:0037 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (27)
- http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html x_refsource_MISCBroken LinkVendor Advisory
- http://contagiodump.blogspot.com/2009/12/virustotal-httpwww.html x_refsource_MISCExploitThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://osvdb.org/60980 vdb-entryx_refsource_OSVDBBroken Link
- http://secunia.com/advisories/37690 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/38138 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/38215 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://www.adobe.com/support/security/advisories/apsa09-07.html x_refsource_CONFIRMVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb10-02.html x_refsource_CONFIRMNot Applicable
- http://www.kb.cert.org/vuls/id/508357 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.metasploit.com/redmine/projects/framework/repository/revisions/7881/entry/modules/exploits/windows/fileformat/adobe_media_newplayer.rb x_refsource_MISCBroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0060.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/bid/37331 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214 x_refsource_MISCBroken Link
- http://www.symantec.com/connect/blogs/zero-day-xmas-present x_refsource_MISCBroken Link
- http://www.us-cert.gov/cas/techalerts/TA10-013A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2009/3518 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2010/0103 vdb-entryx_refsource_VUPENBroken Link
- https://access.redhat.com/security/cve/CVE-2009-4324 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=547799 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-4292 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54747 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2009-4324
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6795 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-4324 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2009-4324
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Dec 15, 2009
Updated Oct 22, 2025
Reserved Dec 14, 2009
Link CVE-2009-4324
CISA Vulnrichment
Updated Feb 4, 2025
ENISA EUVD
EUVD-2009-4292 Assigner adobe
Published Dec 15, 2009
Updated Oct 22, 2025
Exploited since Jun 8, 2022
Link EUVD-2009-4292