PT-2010-1309 · Adobe · Reader+1

Tomas Hoger

·

Published

2010-01-13

·

Updated

2025-02-13

·

CVE-2009-3953

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Reader and Acrobat versions 9.x before 9.3 Adobe Reader and Acrobat versions 8.x before 8.2 Adobe Reader and Acrobat versions 7.x before 7.1.4
Description The issue is related to a problem in the U3D implementation, allowing remote attackers to execute arbitrary code via malformed U3D data in a PDF document. This is due to an "array boundary issue" in the CLODProgressiveMeshDeclaration.
Recommendations For Adobe Reader and Acrobat versions 9.x before 9.3, update to version 9.3 or later. For Adobe Reader and Acrobat versions 8.x before 8.2, update to version 8.2 or later. For Adobe Reader and Acrobat versions 7.x before 7.1.4, update to version 7.1.4 or later.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2009-3953
RHSA-2010:0037
RHSA-2010:0038
RHSA-2010:0060

Affected Products

Acrobat
Reader