CERT-In Vulnerability Note
CIVN-2011-0179
Adobe Acrobat/Reader U3D Memory Corruption Vulnerability
Original Issue Date:December 09, 2011
Severity Rating: HIGH
Systems Affected
- Adobe Reader X (10.1.1) and earlier 10.x versions for Windows and Macintosh
- Adobe Reader 9.4.6 and earlier 9.x versions for Windows, Macintosh and UNIX
- Adobe Acrobat X (10.1.1) and earlier 10.x versions for Windows and Macintosh
- Adobe Acrobat 9.4.6 and earlier 9.x versions for Windows and Macintosh
Overview
A vulnerability has been reported in Adobe Acrobat/Reader which could be exploited by a remote attacker to cause arbitrary code to be executed on the target user's system.
Description
The vulnerability is due to an memory corruption error while handling U3D data . A remote attacker could exploit the vulnerability by creating a specially crafted PDF file that when loaded by the target user will trigger a memory corruption error and execute arbitrary code on the target system. This allows the code to run with the privileges of the target user.
It has been reported that the vulnerability is being actively exploited in limited, targeted attacks in the wild against Adobe Reader 9.x on Windows.
Workaround
- Enable Protected Mode in Adobe Acrobat/Reader.
Solution
Apply appropriate update as mentioned in
APSA 11-04
Vendor Information
Adobe
http://www.adobe.com/support/security/advisories/apsa11-04.html
References
Securitytracker
http://securitytracker.com/id/1026376
Secunia
http://secunia.com/advisories/47133
CVE Name
CVE-2011-2462
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|