English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Adobe Reader JavaScript Methods Memory Corruption


Secunia ID

SA34924

CVE-ID

CVE-2009-1492, CVE-2009-1493

Release Date

28 Apr 2009

Last Change

13 May 2009

Criticality

Highly Critical

Solution Status

Partial Fix

Software

Adobe Acrobat 3D 8.x
Adobe Acrobat 7 Professional
Adobe Acrobat 7.x
Adobe Acrobat 8 Professional
Adobe Acrobat 8.x
Adobe Acrobat 9.x
Adobe Reader 7.x
Adobe Reader 8.x
Adobe Reader 9.x

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Description

Arr1val has discovered two vulnerabilities in Adobe Reader, which can be exploited by malicious people to potentially compromise a user's system.

1) An error when processing calls to the "getAnnots()" JavaScript method can be exploited to corrupt memory via a specially crafted PDF file.

2) An error when processing calls to the "customDictionaryOpen()" JavaScript method can be exploited to corrupt memory via a specially crafted PDF file.

Successful exploitation may allow execution of arbitrary code.

The vulnerabilities are confirmed in version 9.1 for Linux. Other versions may also be affected.

Solution

Update to a fixed version. Please see the vendor's advisory for more information.

Adobe Reader/Acrobat 9.x:
Update to version 9.1.1.

Adobe Reader/Acrobat 8.x:
Update to version 8.1.5.

Adobe Reader/Acrobat 7.x for Windows:
Update to version 7.1.2.

Adobe Reader/Acrobat 7.x for Macintosh:
Updates will reportedly be available before the end of June. Disable JavaScript support.

Reported by

Arr1val

Original Advisory

Arr1val:
http://packetstorm.linuxsecurity.com/0904-exploits/spell.txt
http://packetstorm.linuxsecurity.com/0904-exploits/getannots.txt

Adobe:
http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html
http://www.adobe.com/support/security/advisories/apsa09-02.html
http://www.adobe.com/support/security/bulletins/apsb09-06.html