This application requires Javascript for optimal performance.

Adobe.Reader.Decode.Color.Remote.Code.Execution

Release Date

Oct 09, 2009

Severity

critical

Impact

System Compromise.

Description

This indicates an attempt to exploit a remote code execution vulnerability in Adobe Reader and Acrobat.

This vulnerability is caused by an unspecified memory corruption error, which could be exploited by attackers to execute arbitrary code via a specially crafted PDF file.

Affected Products

Adobe Reader version 9.1.3 and earlier
Adobe Acrobat version 9.1.3 and earlier

Recommended Actions

Upgrade to the latest Adobe Acrobat and Reader versions from the vendor:
http://www.adobe.com/

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-3459

Reference/s

http://www.adobe.com/support/security/bulletins/apsb09-15.html
http://www.securityfocus.com/bid/36600 (BugTraq)

Reference: VID-17776