PT-2010-1309 · Adobe · Reader+1
Tomas Hoger
·
Published
2010-01-13
·
Updated
2025-02-13
·
CVE-2009-3953
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Reader and Acrobat versions 9.x before 9.3
Adobe Reader and Acrobat versions 8.x before 8.2
Adobe Reader and Acrobat versions 7.x before 7.1.4
Description
The issue is related to a problem in the U3D implementation, allowing remote attackers to execute arbitrary code via malformed U3D data in a PDF document. This is due to an "array boundary issue" in the CLODProgressiveMeshDeclaration.
Recommendations
For Adobe Reader and Acrobat versions 9.x before 9.3, update to version 9.3 or later.
For Adobe Reader and Acrobat versions 8.x before 8.2, update to version 8.2 or later.
For Adobe Reader and Acrobat versions 7.x before 7.1.4, update to version 7.1.4 or later.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acrobat
Reader