CVE-2009-3956: XSS
Adobe Security Bulletin for Adobe Reader and Acrobat APSB10-02 fixes following security flaw:
This update mitigates a script injection vulnerability by changing the Enhanced Security default (CVE-2009-3956).
Other sources
The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2009-3956?
CVE-2009-3956 has a severity rating that indicates a potential risk stemming from script injection vulnerabilities.
How do I fix CVE-2009-3956?
To fix CVE-2009-3956, update Adobe Reader or Acrobat to versions 9.3 or later.
What is the impact of CVE-2009-3956?
The impact of CVE-2009-3956 relates to the potential for attackers to execute harmful scripts through Adobe Reader or Acrobat.
Which versions of software are affected by CVE-2009-3956?
CVE-2009-3956 affects Adobe Reader and Acrobat versions 9.x before 9.3 and 8.x before 8.2 on both Windows and Mac OS X.
Is CVE-2009-3956 specific to any operating system?
CVE-2009-3956 affects both Windows and Mac OS X platforms.