CVE-2010-2862: Integer Overflow
Published Aug 5, 2010
·Updated
Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote attackers to execute arbitrary code via a TrueType font with a large maxCompositePoints value in a Maximum Profile (maxp) table.
Affected Software
3 affected components
Adobe Acrobat reader=8.2.3
Adobe Acrobat reader=9.3.3
Adobe Acrobat=9.3.3
Event History
Aug 5, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
Which installations are affected?
The affected products are Adobe Reader 8.2.3 and 9.3.3, plus Adobe Acrobat 9.3.3. The vulnerable component is CoolType.dll.
2
What must an attacker provide to exploit this issue?
An attacker needs to supply a TrueType font containing a large maxCompositePoints value in the Maximum Profile (maxp) table. The issue can be exploited remotely and does not require authentication.
3
What is the potential impact of successful exploitation?
Successful exploitation can allow remote execution of arbitrary code. The listed impact includes compromise of confidentiality, integrity, and availability.