Acrobat and Reader are prone to an overflow condition. The programs fail to properly sanitize user-supplied input resulting in an array overflow. With a specially crafted PDF file containing malformed U3D data, a context-dependent attacker can potentially cause arbitrary code execution.
Classification
Location:
Local / Remote,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Vendor Verified,
Coordinated Disclosure
Solution
Upgrade Reader to version 9.2 or higher and Acrobat users to upgrade to version 7.1.4, 8.1.7, 9.2 or higher as it has been reported to fix this vulnerability. Adobe has provided updates to Reader 7.1.4 and 8.1.7.