This application requires Javascript for optimal performance.

Adobe.U3D.CLOD.Mesh.Declaration.Array.Buffer.Overflow

Release Date

Dec 17, 2009

Severity

critical

Impact

System Compromise

Description

This indicates a possible attack against a buffer-overflow vulnerability in Adobe Reader and Acrobat.

The vulnerability is caused by improper checking of user-supplied input. A remote attacker may expoit this to execute arbitrary code via a specially crafted .pdf file.

Affected Products

Adobe Reader 9.2 and earlier versions for Windows, Macintosh, and UNIX
Adobe Acrobat 9.2 and earlier versions for Windows and Macintosh

Recommended Actions

An update is available at the following webpage:
http://www.adobe.com/support/security/bulletins/apsb10-02.html

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-3953

Reference/s

http://www.adobe.com/support/security/bulletins/apsb10-02.html
http://www.securityfocus.com/bid/37758 (BugTraq)

Reference: VID-17987