First published: Mon Apr 05 2010(Updated: )
Heap-based buffer overflow in the custom heap management system in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, aka FG-VD-10-005.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader Notification Manager | =8.0 | |
Adobe Acrobat Reader Notification Manager | =8.1 | |
Adobe Acrobat Reader Notification Manager | =8.1.1 | |
Adobe Acrobat Reader Notification Manager | =8.1.2 | |
Adobe Acrobat Reader Notification Manager | =8.1.4 | |
Adobe Acrobat Reader Notification Manager | =8.1.5 | |
Adobe Acrobat Reader Notification Manager | =8.1.6 | |
Adobe Acrobat Reader Notification Manager | =8.1.7 | |
Adobe Acrobat Reader Notification Manager | =8.2 | |
Adobe Acrobat Reader Notification Manager | =8.2.1 | |
Adobe Acrobat Reader Notification Manager | =9.0 | |
Adobe Acrobat Reader Notification Manager | =9.1 | |
Adobe Acrobat Reader Notification Manager | =9.1.1 | |
Adobe Acrobat Reader Notification Manager | =9.1.2 | |
Adobe Acrobat Reader Notification Manager | =9.1.3 | |
Adobe Acrobat Reader Notification Manager | =9.2 | |
Adobe Acrobat Reader Notification Manager | =9.3 | |
Adobe Acrobat Reader Notification Manager | =9.3.1 | |
Apple iOS and macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1241 has a high severity rating due to its potential for remote code execution and denial of service.
To fix CVE-2010-1241, users should upgrade to Adobe Reader and Acrobat version 9.3.2 or higher, or 8.2.2 or higher.
CVE-2010-1241 affects Adobe Reader and Acrobat on Windows and Mac OS X platforms.
Yes, CVE-2010-1241 can be exploited via specially crafted PDF documents sent by remote attackers.
Exploitation of CVE-2010-1241 could lead to arbitrary code execution or memory corruption, resulting in a denial of service.