|
|
|
|
| |
Credit:
The information has been provided by ZDI Disclosures.
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-09-042
|
| |
Vulnerable Systems:
* Adobe Acrobat version 9.1.1 and earlier
* Adobe Reader version 9.1.1 and earlier
Immune Systems:
* Adobe Acrobat version 9.1.2 and later
* Adobe Reader version 9.1.2 and later
The specific flaw exists when parsing malformed U3D model files contained in a PDF. When a specially crafted extension block of a model is processed, insufficient bounds checking is done before a call to wcsncpy(). Because of this a stack overflow can occur resulting in reliable code execution. Proper exploitation of this vulnerability will result in system compromise under the credentials of the currently logged in user.
CVE Information:
CVE-2009-1855
Vendor Response:
Adobe has issued an update to correct this vulnerability. More details can be found at: http://www.adobe.com/support/security/bulletins/apsb09-07.html
Disclosure Timeline:
2009-02-24 - Vulnerability reported to vendor
2009-06-10 - Coordinated public release of advisory
|
|
|
|
|