SB2010080701 - Two vulnerabilities in Adobe Reader and Acrobat



SB2010080701 - Two vulnerabilities in Adobe Reader and Acrobat

Published: August 7, 2010 Updated: January 21, 2017

Security Bulletin ID SB2010080701
Severity
Critical
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 50% Medium 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Code execution (CVE-ID: CVE-2010-1240)

The vulnerability allows a remote attacker to compromise vulnerable system using social engineering attack.

The vulnerability exists due to unspecified error. A remote attacker can use social engineering attack to trick the victim into executing arbitrary code on vulnerable system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


2) Integer overflow (CVE-ID: CVE-2010-2862)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in CoolType.dll when processing TrueType fonts with a large maxCompositePoints value in a Maximum Profile (maxp) table within PDF files. A remote attacker can create a specially crafted PDF file, trick the victim into opening it and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Note: this vulnerability is being actively exploited in the wild.



Remediation

Install update from vendor's website.