Secunia CSI 5.0
Overview
Advisories
Research
Forums
Create Profile
Our Commitment
Database
Search
Advisories by Product
Advisories by Vendor
Terminology
Report Vulnerability
Insecure Library Loading

Secunia Advisory SA39272

Adobe Reader / Acrobat Multiple Vulnerabilities
Secunia Advisory SA39272
DOWNLOAD CSI


DOWNLOAD PSI
Release Date 2010-04-14
Last Update 2010-05-12
   
Popularity 18,698 views
Comments 13 comments

Criticality level Highly criticalHighly critical
Impact Cross Site Scripting
System access
Where From remote
Authentication level Available in Customer Area
   
Report reliability Available in Customer Area
Solution Status Vendor Patch
   
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
Remediation status Secunia CSI, Secunia PSI
Automated scanning Secunia CSI, Secunia PSI
   
Software:
Adobe Acrobat 3D 8.x
Adobe Acrobat 8 Professional
Adobe Acrobat 8.x
Adobe Acrobat 9.x
Adobe Reader 8.x
Adobe Reader 9.x

Secunia CVSS Score Available in Customer Area
CVE Reference(s) CVE-2010-0190 CVSS available in Customer Area
CVE-2010-0191 CVSS available in Customer Area
CVE-2010-0192 CVSS available in Customer Area
CVE-2010-0193 CVSS available in Customer Area
CVE-2010-0194 CVSS available in Customer Area
CVE-2010-0195 CVSS available in Customer Area
CVE-2010-0196 CVSS available in Customer Area
CVE-2010-0197 CVSS available in Customer Area
CVE-2010-0198 CVSS available in Customer Area
CVE-2010-0199 CVSS available in Customer Area
CVE-2010-0201 CVSS available in Customer Area
CVE-2010-0202 CVSS available in Customer Area
CVE-2010-0203 CVSS available in Customer Area
CVE-2010-0204 CVSS available in Customer Area
CVE-2010-1241 CVSS available in Customer Area
  

Description

Multiple vulnerabilities have been reported in Adobe Reader and Adobe Acrobat, which can be exploited by malicious people to conduct cross-site scripting attacks or compromise a user's system.

1) An unspecified error can be exploited to conduct cross-site scripting attacks.

2) An unspecified "prefix protocol handler" error may allow code execution.

3) An unspecified error may be exploited to execute arbitrary code.

4) An unspecified error may be exploited to execute arbitrary code.

5) An error in the X3D component (3difr.x3d) when processing a DeviceRGB sub-type stream can be exploited to corrupt memory and may allow execution of arbitrary code.

6) An index calculation error in the parsing of certain tables in embedded fonts may allow code execution.

7) An integer overflow error when parsing the "Shading Count" field of a CLOD Mesh Declaration block in U3D data can potentially be exploited to cause a heap-based buffer overflow and execute arbitrary code.

NOTE: Reportedly, this vulnerability only affects Adobe Reader for Linux.

8) An unspecified error can be exploited to corrupt memory and may allow execution of arbitrary code.

9) An uninitialised memory error when processing JPEG images can be exploited to dereference out-of-bounds data and may allow execution of arbitrary code.

10) A boundary error when processing GIF images can be exploited to cause a buffer overflow and may allow execution of arbitrary code.

11) An unspecified error can be exploited to corrupt memory and may allow execution of arbitrary code.

12) An integer overflow error when processing various image types (e.g. BMP and PNG) can be exploited to cause a heap-based buffer overflow and may allow execution of arbitrary code.

13) An unspecified error can be exploited to corrupt memory and may allow execution of arbitrary code.

14) An error in CoolType.dll when parsing CFF encodings can be exploited to cause a heap-based buffer overflow and may allow execution of arbitrary code.

The vulnerabilities are reported in versions 9.3.1 and prior and versions 8.2.1 and prior.


Solution
Update to version 9.3.2 or 8.2.2.
Further details available in Customer Area

Provided and/or discovered by
1, 2) The vendor credits Billy Rios and Microsoft Vulnerability Research (MSVR).
3) The vendor credits Aki Helin, Oulu University Secure Programming Group.
4) The vendor credits Microsoft Vulnerability Research Program (MSVR).
5) Bing Liu, Fortinet's FortiGuard Labs.
6) An anonymous person via ZDI.
7) TELUS Security Labs.
8) The vendor credits James Quirk.
9, 10, 12) The vendor credits Nicolas Joly, Vupen.
11) The vendor credits Felipe Andres Manzano via iSIGHT Partners Global Vulnerability Partnership.
13) The vendor credits Greg MacManus, iSIGHT Partners Labs.
14) Haifei Li, Fortinet's FortiGuard Labs.

Changelog
Further details available in Customer Area

Original Advisory
Adobe:
http://www.adobe.com/support/security/bulletins/apsb10-09.html

ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-10-071/

TELUS Security Labs:
http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0203.html

Technical Analysis
Further details available in Customer Area

Alternate/detailed remediation
Further details available in Customer Area

Deep Links
Links available in Customer Area


Do you have additional information related to this advisory?

Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com

Subject: Adobe Reader / Acrobat Multiple Vulnerabilities
 
User Message
[+]

pc.tech1

RE: Adobe Reader / Acrobat Multiple Vulnerabilities
This reply has been minimised due to a negative Relevancy Score.
ddmarshall RE: Adobe Reader / Acrobat Multiple Vulnerabilities
Dedicated Contributor 14th Apr, 2010 15:22
Score: 974
Posts: 771
User Since: 8th Nov 2008
System Score: 100%
Location: UK
Install 9.3.2 via the update option on the Help Menu.
Was this reply relevant?
+5
-5

frsecure

RE: Adobe Reader / Acrobat Multiple Vulnerabilities
[+]
This reply has been minimised due to a negative Relevancy Score.

frsecure

RE: Adobe Reader / Acrobat Multiple Vulnerabilities
[+]
This reply has been minimised due to a negative Relevancy Score.
altena RE: Adobe Reader / Acrobat Multiple Vulnerabilities
Member 19th Apr, 2010 14:38
Score: -1
Posts: 2
User Since: 31st Jan 2010
System Score: N/A
Location: N/A
I have the same problem with Acrobat (editor, not reader).
The Help About box says it's version 8.1.2.
The EXE says it's file version 8.1.0.137.
Secuina PSI says it's version 8.1.1.20.
I tried running AcrobatUpd820_all_incr.msp but that failed with a message saying it was trying to update the wrong version of the program.
Looking at http://www.adobe.com/support/downloads/product.jsp... it seems that there are a dozen or so updates I need to apply to bring me up to date, none of which are detected by the Updater.
No wonder I'm confused!
Was this reply relevant?
+3
-4

jbezy3

RE: Adobe Reader / Acrobat Multiple Vulnerabilities
[+]
This reply has been minimised due to a negative Relevancy Score.

metaed

RE: Adobe Reader / Acrobat Multiple Vulnerabilities
[+]
This reply has been minimised due to a negative Relevancy Score.

Anthony Wells

RE: Adobe Reader / Acrobat Multiple Vulnerabilities
[+]
This reply has been minimised due to a negative Relevancy Score.

pinkgranite

RE: Adobe Reader / Acrobat Multiple Vulnerabilities
[+]
This reply has been minimised due to a negative Relevancy Score.
thedillpickl RE: Adobe Reader / Acrobat Multiple Vulnerabilities
Contributor 17th Jul, 2010 00:09
Score: 373
Posts: 869
User Since: 3rd May 2009
System Score: 100%
Location: US
(unknown source)
i still have this problem indeed

Also, all others with similar problems.

Please seek solutions to your problem by starting a new thread in the "PSI" thread using Adobe (name of program) as the topic. Explain what the problem is and someone will help you!


Thank you;

Fred

--
XP Home
Chrome, Firefox, IE8
--
consilio et animis
Was this reply relevant?
+1
-0

Pustishka123

RE: Adobe Reader / Acrobat Multiple Vulnerabilities
[+]
This reply has been deleted

Pustishka123

RE: Adobe Reader / Acrobat Multiple Vulnerabilities
[+]
This reply has been deleted

Pustishka123

RE: Adobe Reader / Acrobat Multiple Vulnerabilities
[+]
This reply has been deleted

-

You must be logged in to post a comment.




 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Factsheets
Reports & Papers
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2012 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability