HIGH
Acroread: Heap-based overflow by opening a specially-crafted PDF file (FG-VD-10-005)
Published Apr 5, 2010
9.3
HIGHCVSS 2.0
EPSS 9.21%
Description
Heap-based buffer overflow in the custom heap management system in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, aka FG-VD-10-005.
Affected products
No data.
AND
OR
- 8.0
- 8.1
- 8.1.1
- 8.1.2
- 8.1.4
- 8.1.5
- 8.1.6
- 8.1.7
- 8.2
- 8.2.1
- 9.0
- 9.1
- 9.1.1
- 9.1.2
- 9.1.3
- 9.2
- 9.3
- 9.3.1
No data.
Extras for RHEL 4
acroread-0:9.3.2-1.el4
Fixed · RHSA-2010:0349
Supplementary for Red Hat Enterprise Linux 5
acroread-0:9.3.2-1.el5
Fixed · RHSA-2010:0349
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 4 | acroread-0:9.3.2-1.el4 | Fixed | RHSA-2010:0349 |
| Supplementary for Red Hat Enterprise Linux 5 | acroread-0:9.3.2-1.el5 | Fixed | RHSA-2010:0349 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (16)
- http://blog.fortinet.com/the-upcoming-blackhat-europe-2010-presentation/ x_refsource_MISCExploit
- http://lists.immunitysec.com/pipermail/dailydave/2010-April/006077.html mailing-listx_refsource_MLIST
- http://www.adobe.com/support/security/bulletins/apsb10-09.html x_refsource_CONFIRM
- http://www.blackhat.com/html/bh-eu-10/bh-eu-10-briefings.html#Li x_refsource_MISC
- http://www.securityfocus.com/bid/39227 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/39329 vdb-entryx_refsource_BID
- http://www.us-cert.gov/cas/techalerts/TA10-103C.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2010/0873 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.youtube.com/watch?v=9EVHtY1-0q8 x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2010-1241 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=579213 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-1271 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57589 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2010-1241
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6940 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2010-1241
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 5, 2010
Updated Aug 7, 2024
Reserved Apr 5, 2010
Link CVE-2010-1241
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2010-1271 Assigner mitre
Published Apr 5, 2010
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2010-1271