Adobe Reader/Acrobat TrueType Font Processing Memory Corruption
14 Jun. 2009
Summary
A memory corruption vulnerability exists when processing PDF documents and handling TrueType fonts, which could allow an attacker to execute arbitrary code with the privileges of the current user.
Vulnerable Systems:
* Adobe Reader version 9.1.1
* Adobe Acrobat version 9.1.1 and earlier
Immune Systems:
* Adobe Reader version 9.1.2
* Adobe Acrobat version 9.1.2 and earlier
A crash will sometimes occur when processing a TrueType font within the document, leading to memory corruption and allowing the execution of remote code.