CERT-MU AD-2010-13
Multiple Remote Code Execution Vulnerabilities in Adobe Acrobat and Reader
Original issue date: 27 July, 2010
Overview
Multiple vulnerabilities have been reported in Adobe Acrobat and Reader which could allow remote code execution to take complete control of the systems installed with vulnerable versions of software.
Description
Multiple vulnerabilities have been reported in Adobe Reader and Acrobat, which could allow remote attackers to cause a denial of service or compromise a vulnerable system.
These vulnerabilities are caused due to memory corruptions, invalid pointers, uninitialized memory, array-indexing and use-after-free errors while processing malformed data within a specially crafted PDF document.
A remote attacker could exploit these vulnerabilities by alluring users to open specially crafted malformed PDF document sent via email attachment or via hosting it at purposefully crafted webpage or website. Upon opening, Adobe Reader and Acrobat processing malformed data within malformed PDF, which could cause application crash (Denial of Service (DoS)), execution of arbitrary code and could allow remote attacker to gain system access with the privileges of currently logged-in user.
Workarounds
- Do not opening PDF files received from un-trusted and unknown sources
- Do not open PDF files received unexpectedly from trusted sources
- Disable JavaScript and ActiveX scripting in the browser settings
- Exercise caution while visiting websites links received in emails
- Disable displaying and automatic opening of PDF documents in Web Browser
- Use Adobe automatic update feature
Affected Softwares
-
Adobe Reader 9.3.2 and earlier versions for
- Microsoft Windows
- Macintosh
- UNIX
-
Adobe Acrobat 9.3.2 and earlier versions for
- Microsoft Windows
- Macintosh
Impact
Severity Rating: High
Solution
Install updates as suggested in
APSB10-15
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind
Vendor Information
Adobe Security Bulletin
http://www.adobe.com/support/security/bulletins/apsb10-15.html
CVE Name
CVE-2010-1240
CVE-2010-1285
CVE-2010-1295
CVE-2010-1297
CVE-2010-2168
CVE-2010-2201
CVE-2010-2202
CVE-2010-2203
CVE-2010-2204
CVE-2010-2205
CVE-2010-2206
CVE-2010-2207
CVE-2010-2208
CVE-2010-2209
CVE-2010-2210
CVE-2010-2211
CVE-2010-2212
References
Adobe
http://www.adobe.com/support/security/bulletins/apsb10-15.html
http://www.adobe.com/support/security/advisories/apsa10-01.html
CERT-In
http://www.cert-in.org.in/vulnerability/civn-2010-146.htm
US-CERT
http://www.us-cert.gov/cas/alerts/SA10-159A.html
SecurityTracker
http://securitytracker.com/alerts/2010/Jun/1024159.html
F-Secure
http://www.f-secure.com/vulnerabilities/SA201006476
SecurityFocus
http://www.securityfocus.com/bid/41232
http://www.securityfocus.com/bid/41230
http://www.securityfocus.com/bid/40586
http://www.securityfocus.com/bid/41236
http://www.securityfocus.com/bid/41237
http://www.securityfocus.com/bid/41234
http://www.securityfocus.com/bid/41235
http://www.securityfocus.com/bid/41231
http://www.securityfocus.com/bid/41238
http://www.securityfocus.com/bid/41241
http://www.securityfocus.com/bid/41239
http://www.securityfocus.com/bid/41244
http://www.securityfocus.com/bid/41240
http://www.securityfocus.com/bid/41242
http://www.securityfocus.com/bid/41243
http://www.securityfocus.com/bid/41245
|