[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-3955Date: (C)2010-01-13   (M)2024-02-22


Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted JPC_MS_RGN marker in the Jp2c stream of a JpxDecode encoded data stream, which triggers an integer sign extension that bypasses a sanity check, leading to memory corruption.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1023446
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=836
BID-37757
SECUNIA-38138
SECUNIA-38215
ADV-2010-0103
RHSA-2010:0060
SUSE-SA:2010:008
TA10-013A
acrobat-reader-jpxdecode-code-exec(55553)
http://www.adobe.com/support/security/bulletins/apsb10-02.html
https://bugzilla.redhat.com/show_bug.cgi?id=554293
oval:org.mitre.oval:def:8255

CPE    94
cpe:/a:adobe:acrobat_reader:3.02
cpe:/a:adobe:acrobat_reader:6.0
cpe:/a:adobe:acrobat_reader:6.0.2
cpe:/a:adobe:acrobat_reader:3.01
...
CWE    1
CWE-399
OVAL    5
oval:org.secpod.oval:def:5332
oval:org.mitre.oval:def:8255
oval:org.secpod.oval:def:9998
oval:org.secpod.oval:def:5329
...

© SecPod Technologies