First published: Wed Jun 30 2010(Updated: )
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content involving the (1) pushstring (0x2C) operator, (2) debugfile (0xF1) operator, and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2168.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | =9.0 | |
Adobe Acrobat Reader | =9.1 | |
Adobe Acrobat Reader | =9.1.1 | |
Adobe Acrobat Reader | =9.1.2 | |
Adobe Acrobat Reader | =9.1.3 | |
Adobe Acrobat Reader | =9.2 | |
Adobe Acrobat Reader | =9.3 | |
Adobe Acrobat Reader | =9.3.1 | |
Adobe Acrobat Reader | =9.3.2 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
Adobe Acrobat Reader Notification Manager | =9.0 | |
Adobe Acrobat Reader Notification Manager | =9.1 | |
Adobe Acrobat Reader Notification Manager | =9.1.1 | |
Adobe Acrobat Reader Notification Manager | =9.1.2 | |
Adobe Acrobat Reader Notification Manager | =9.1.3 | |
Adobe Acrobat Reader Notification Manager | =9.2 | |
Adobe Acrobat Reader Notification Manager | =9.3 | |
Adobe Acrobat Reader Notification Manager | =9.3.1 | |
Adobe Acrobat Reader Notification Manager | =9.3.2 | |
Adobe Acrobat Reader | =8.0 | |
Adobe Acrobat Reader | =8.1 | |
Adobe Acrobat Reader | =8.1.1 | |
Adobe Acrobat Reader | =8.1.2 | |
Adobe Acrobat Reader | =8.1.3 | |
Adobe Acrobat Reader | =8.1.4 | |
Adobe Acrobat Reader | =8.1.5 | |
Adobe Acrobat Reader | =8.1.6 | |
Adobe Acrobat Reader | =8.1.7 | |
Adobe Acrobat Reader | =8.2 | |
Adobe Acrobat Reader | =8.2.1 | |
Adobe Acrobat Reader | =8.2.2 | |
Adobe Acrobat Reader Notification Manager | =8.0 | |
Adobe Acrobat Reader Notification Manager | =8.1 | |
Adobe Acrobat Reader Notification Manager | =8.1.1 | |
Adobe Acrobat Reader Notification Manager | =8.1.2 | |
Adobe Acrobat Reader Notification Manager | =8.1.4 | |
Adobe Acrobat Reader Notification Manager | =8.1.5 | |
Adobe Acrobat Reader Notification Manager | =8.1.6 | |
Adobe Acrobat Reader Notification Manager | =8.1.7 | |
Adobe Acrobat Reader Notification Manager | =8.2.1 | |
Adobe Acrobat Reader Notification Manager | =8.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2201 is classified as critical due to its potential to allow remote code execution through malicious PDF files.
To fix CVE-2010-2201, update Adobe Reader and Acrobat to version 9.3.3 or later for version 9.x, and to version 8.2.3 or later for version 8.x.
CVE-2010-2201 affects Adobe Reader and Acrobat versions 8.x and 9.x on both Windows and Mac OS X.
CVE-2010-2201 is a security vulnerability that exploits crafted Flash content within PDF files leading to arbitrary code execution.
Using affected versions of Adobe Reader and Acrobat is unsafe as they are susceptible to exploitations unless patched.