Security Advisory for Adobe Reader and Acrobat
Release date: September 8, 2010
Vulnerability identifier: APSA10-02
CVE number: CVE-2010-2883
Platform: All
SUMMARY
A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.
Adobe is in the process of evaluating the schedule for an update to resolve this vulnerability.
AFFECTED SOFTWARE VERSIONS
Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh.
SEVERITY RATING
Adobe categorizes this as a critical issue.
DETAILS
A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. Adobe is aware of public exploit code for this vulnerability.
Adobe is in the process of evaluating the schedule for an update to resolve this vulnerability.
Adobe actively shares information about this and other vulnerabilities with partners in the security community to enable them to quickly develop detection and quarantine methods to protect users until a patch is available. As always, Adobe recommends that users follow security best practices by keeping their anti-malware software and definitions up to date.
Users may monitor the latest information on the Adobe Product Security Incident Response Team blog at the following URL:http://blogs.adobe.com/psirt or by subscribing to the RSS feed here: http://blogs.adobe.com/psirt/atom.xml.
ACKNOWLEDGMENTS
Adobe would like to thank Mila Parkour of http://contagiodump.blogspot.com for working on this issue with Adobe to help protect our customers.
'취약점소식' 카테고리의 다른 글
[Adobe] Adobe Reader/Acrobat 다중 취약점 보안 업데이트 권고 (0) | 2010.10.07 |
---|---|
[Adobe] Adobe Flash Player 원격코드실행 취약점 주의 (2) | 2010.09.15 |
[Apple] 애플 퀵타임 플레이어 원격코드실행 취약점 주의 (0) | 2010.09.01 |
[MS] DLL 하이재킹 취약점으로 인한 악성코드 감염 주의 (0) | 2010.08.26 |
[MS] 윈도우 서비스 격리 기능 우회 취약점 주의 (3) | 2010.08.13 |
댓글