Release DateApr 30, 2010 |
Severitymedium |
ImpactArbitrary command execution |
DescriptionThis indicates an attempt to download a PDF file with a launch action that provides a way to launch a command and may ultimately run an executable. |
Affected ProductsAdobe ReaderFoxit Reader |
Recommended ActionsApply the patch from the vendor:http://www.adobe.com/support/security/bulletins/apsb10-15.html |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2009-0837CVE-2010-1240 |
Reference/shttp://www.adobe.com/support/security/bulletins/apsb10-15.htmlhttp://blog.didierstevens.com/2010/03/29/escape-from-pdf/ http://www.securityfocus.com/bid/34035 (BugTraq) |