Release date: 2011-12-06
Updated on: 2011-12-07
Affected Systems:
Adobe Reader 9.x
Adobe Reader 10.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50922
Cve id: CVE-2011-2462
Adobe Reader (also known as Acrobat Reader) is an excellent PDF document reading software developed by Adobe. Acrobat is a series of products launched in 1993 for enterprises, technicians and creative professionals, making smart document delivery and collaboration more flexible, reliable, and secure.
Adobe Acrobat and Reader have a memory corruption vulnerability when processing malformed structures contained in U3D data. Attackers can exploit this vulnerability to crash and completely control the affected system.
<* Source: Lockheed Martin CIRT
MITRE
Link: http://www.adobe.com/support/security/advisories/apsa11-04.html
*>
Suggestion:
--------------------------------------------------------------------------------
Temporary solution:
If you cannot install or upgrade the patch immediately, NSFOCUS recommends that you take the following measures to reduce the threat:
* Do not use Adobe Reader to open a PDF file of unknown source. Use other PDF File Viewing tools, such as Foxit.
Vendor patch:
Adobe
-----
Adobe has released a Security Bulletin (APSA11-04) for this, but has not provided the appropriate patch:
APSA11-04: Security Advisory for Adobe Reader and Acrobat
Link: http://www.adobe.com/support/security/advisories/apsa11-04.html