CVE Database
/

CVE-2009-3955

Back to search

CVE-2009-3955

Published: Jan 13, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted JPC_MS_RGN marker in the Jp2c stream of a JpxDecode encoded data stream, which triggers an integer sign extension that bypasses a sanity check, leading to memory corruption.

VendorProductVersions

n/a

n/a

affected
n/a

References

38138
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:8255
vdb-entry
signature
x_refsource_OVAL
RHSA-2010:0060
vendor-advisory
x_refsource_REDHAT
ADV-2010-0103
vdb-entry
x_refsource_VUPEN
1023446
vdb-entry
x_refsource_SECTRACK
38215
third-party-advisory
x_refsource_SECUNIA
37757
vdb-entry
x_refsource_BID
SUSE-SA:2010:008
vendor-advisory
x_refsource_SUSE
TA10-013A
third-party-advisory
x_refsource_CERT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now