Array index error in AcroForm.api in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted GIF image in a PDF file, which bypasses a size check and triggers a heap-based buffer overflow.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2010/1636 | vdb entry |
http://www.adobe.com/support/security/bulletins/apsb10-15.html | patch vendor advisory |
http://www.securityfocus.com/archive/1/512092/100/0/threaded | mailing list |
http://secunia.com/secunia_research/2010-88/ | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7200 | vdb entry signature |
http://www.securitytracker.com/id?1024159 | vdb entry |
http://www.securityfocus.com/bid/41241 | vdb entry |