HTTP: PDF U3D RHAdobeMeta Buffer Overflow

This signature detects attempts to exploit a known vulnerability in Adobe Acrobat. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the user.

Extended Description

Adobe Reader and Acrobat are prone to a remote stack-based buffer-overflow vulnerability because they fail to adequately bounds-check user-supplied data. An attacker can exploit this issue by tricking a victim into opening a malicious file to execute arbitrary code and to cause denial-of-service conditions. NOTE: This issue was previously covered in BID 35274 (Adobe Reader and Acrobat 9.1.1 and Prior Multiple Remote Vulnerabilities), but has been assigned its own record to better document it.

Affected Products

Nortel_networks self-service_speech_server,Red_hat enterprise_linux_as_extras

References

BugTraq: 35282

CVE: CVE-2009-1855

Short Name
HTTP:STC:ADOBE:PDF-U3D-BO
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Buffer CVE-2009-1855 Overflow PDF RHAdobeMeta U3D bid:35282
Release Date
09/29/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Red_hat

Adobe

Gentoo

Sun

Avaya

Nortel_networks

Suse

CVSS Score

9.3

Found a potential security threat?