This application requires Javascript for optimal performance.

Adobe.Reader.U3D.Progressive.Mesh.Block.Code.Execution

Release Date

Oct 22, 2009

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to exploit a memory corruption vulnerability in Adobe Reader.

The vulnerability is caused by an error that occurs when the vulnerable software parses a malformed CLOD Progressive Mesh Continuation Block in U3D file embeded in a PDF files. It allows a remote attacker to execute arbitrary code via sending a crafted PDF file.

Affected Products

Adobe Reader 9.1.3 and older versions.

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-2990
CVE-2009-3458

Reference/s

http://www.securityfocus.com/bid/36665 (BugTraq)

Reference: VID-17795