Back

HIGH KEV

Acroread: Stack-based buffer overflow by processing certain fonts (APSA10-02)

Published Sep 9, 2010 ·Due Jun 22, 2022

Description

Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Sep 9, 2010
Updated Oct 22, 2025
Reserved Jul 27, 2010
CISA Vulnrichment
Updated Feb 4, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Sep 8, 2010