CVE-2009-3955: Critical severity adobe acrobat reader vulnerability
Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted JPCMSRGN marker in the Jp2c stream of a JpxDecode encoded data stream, which triggers an integer sign extension that bypasses a sanity check, leading to memory corruption.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2009-3955?
CVE-2009-3955 is rated as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2009-3955?
To fix CVE-2009-3955, users should update Adobe Reader and Acrobat to version 9.3 or higher.
Which versions of Adobe products are affected by CVE-2009-3955?
CVE-2009-3955 affects Adobe Reader and Acrobat 9.x before 9.3 and 8.x before 8.2.
What platforms are impacted by CVE-2009-3955?
CVE-2009-3955 affects versions of Adobe Reader and Acrobat on both Windows and Mac OS X.
Can CVE-2009-3955 be exploited remotely?
Yes, CVE-2009-3955 can be exploited remotely through a crafted JPC_MS_RGN marker within a manipulated Jp2c stream.