Adobe.Reader.Spell.CustomDictionaryOpen

NameAdobe.Reader.Spell.CustomDictionaryOpen.Code.Execution
Last Updated DateJun 23, 2009
Release DateMay 04, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a vulnerability in Adobe Reader and Acrobat.

This vulnerability is caused by a memory corruption error when the vulnerable software handles malicious data passed to the JavaScript method "customDictionaryOpen". It may allow a remote attacker to execute arbitrary code via sending a crafted PDF file.
Affected ProductsAdobe Acrobat Reader 8.1.4
Adobe Acrobat Reader 9.1
Recommended ActionsCurrently we are not aware of any patches supplied by the vendor for this issue.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1493
Reference/shttp://www.securityfocus.com/bid/34740 (BugTraq)
http://www.vupen.com/english/advisories/2009/1189 (FrSIRT)
http://www.milw0rm.com/exploits/8570
Reference: VID-17415