English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Adobe Reader/Acrobat Two Vulnerabilities


Secunia ID

SA38551

CVE-ID

CVE-2010-0186, CVE-2010-0188

Release Date

12 Feb 2010

Last Change

17 Feb 2010

Criticality

Highly Critical

Solution Status

Vendor Patch

Software

Adobe Acrobat 3D 8.x
Adobe Acrobat 8 Professional
Adobe Acrobat 8.x
Adobe Acrobat 9.x
Adobe Reader 8.x
Adobe Reader 9.x

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Security Bypass

This covers vulnerabilities or security issues where malicious users or people can bypass certain security mechanisms of the application.

The actual impact varies significantly depending on the design and purpose of the affected application.

Description

Two vulnerabilities have been reported in Adobe Reader and Acrobat, which can be exploited by malicious people to bypass certain security restrictions or compromise a user's system.

1) An error in the included Flash player can be exploited to perform unauthorized cross-domain requests.

For more information:
SA38547

2) An unspecified error can be exploited to cause a crash or potentially execute arbitrary code.

The vulnerabilities are reported in Adobe Reader and Adobe Acrobat versions 9.3 and prior.

Solution

Update to version 8.2.1 or 9.3.1.

Adobe Reader on Windows:
http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows

Adobe Reader on Macintosh:
http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Macintosh

Adobe Reader on UNIX:
http://www.adobe.com/products/reader/unix9/

Acrobat Standard and Pro on Windows:
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows

Acrobat Pro Extended on Windows:
http://www.adobe.com/support/downloads/product.jsp?product=158&platform=Windows

Acrobat 3D on Windows:
http://www.adobe.com/support/downloads/product.jsp?product=112&platform=Windows

Acrobat Pro on Macintosh:
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Macintosh

Reported by

2) The vendor credits the Microsoft Vulnerability Research Program (MSVR).

Original Advisory

http://www.adobe.com/support/security/bulletins/apsb10-07.html