|
|
| |
Credit:
The information has been provided by binaryproof.
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-11-300/
|
| |
Vulnerable Systems:
* Adobe Reader
User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the way Adobe handles PICT images. When Adobe parses a PICT image containing an 0x10 opcode the following word in the file will be interpreted as a loop counter that copies data from the file into a heap buffer that has been created using the height and with of the picture. The resulting heap overflow can result in remote code execution under the rights of the current user.
Patch Availability:
Adobe has issued an update to correct this vulnerability. More details can be found at:
http://www.adobe.com/support/security/bulletins/apsb11-24.html
CVE Information:
CVE-2011-2433
Disclosure Timeline:
2011-05-12 - Vulnerability reported to vendor
2011-10-26 - Coordinated public release of advisory
|
|
|