CVE-2010-3624: Input Validation
Published Oct 6, 2010
·Updated
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allows attackers to execute arbitrary code via a crafted image.
Affected Software
49 affected components
Adobe Acrobat=8.0
Adobe Acrobat=8.1.7
Adobe Acrobat=8.2.1
Adobe Acrobat=8.1.2
Adobe Acrobat reader=8.1.6
Adobe Acrobat reader=8.2.3
Adobe Acrobat reader=8.2
Adobe Acrobat reader=8.2.2
Adobe Acrobat=8.2.4
Adobe Acrobat=8.1.1
Adobe Acrobat reader=8.2.4
Adobe Acrobat=8.2.3
Adobe Acrobat=8.2
Adobe Acrobat=8.1
Adobe Acrobat reader=8.0
Adobe Acrobat reader=8.1.5
Adobe Acrobat=8.2.2
Adobe Acrobat reader=8.2.1
Adobe Acrobat reader=8.1.7
Adobe Acrobat reader=8.1.4
Adobe Acrobat=8.1.5
Adobe Acrobat=8.1.4
Adobe Acrobat reader=8.1.2
Adobe Acrobat reader=8.1.1
Adobe Acrobat reader=8.1
Adobe Acrobat=8.1.6
Adobe Acrobat=8.1.3
Adobe Acrobat=9.3.3
Adobe Acrobat=9.2
Adobe Acrobat=9.1
Adobe Acrobat reader=9.2
Adobe Acrobat reader=9.1
Adobe Acrobat reader=9.1.3
Adobe Acrobat=9.0
Adobe Acrobat reader=9.1.2
Adobe Acrobat=9.3.4
Adobe Acrobat reader=9.3.3
Adobe Acrobat reader=9.1.1
Adobe Acrobat=9.3.2
Adobe Acrobat=9.1.1
Adobe Acrobat reader=9.3.4
Adobe Acrobat reader=9.3
Adobe Acrobat reader=9.0
Adobe Acrobat reader=9.3.2
Adobe Acrobat=9.3.1
Adobe Acrobat=9.1.2
Adobe Acrobat reader=9.3.1
Adobe Acrobat=9.1.3
Adobe Acrobat=9.3
Remediation
Event History
Oct 6, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3624?
CVE-2010-3624 is considered a critical vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2010-3624?
To fix CVE-2010-3624, users should update Adobe Reader and Acrobat to version 9.4 or later, or 8.2.5 or later for version 8.
3
Who is affected by CVE-2010-3624?
CVE-2010-3624 affects Adobe Reader and Acrobat versions 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X.
4
What type of attack can CVE-2010-3624 facilitate?
CVE-2010-3624 can facilitate remote code execution attacks through crafted images.
5
Is there a workaround for CVE-2010-3624?
A recommended workaround for CVE-2010-3624 is to avoid opening untrusted PDF documents until the software is updated.