CVE-2011-0592: Input Validation
Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a crafted Universal 3D (U3D) file that triggers a buffer overflow during decompression, related to "Texture bmp," a different vulnerability than CVE-2011-0590, CVE-2011-0591, CVE-2011-0593, CVE-2011-0595, and CVE-2011-0600.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0592?
CVE-2011-0592 is considered a critical vulnerability that allows remote code execution.
How do I fix CVE-2011-0592?
To fix CVE-2011-0592, users should update Adobe Reader and Acrobat to the latest versions and apply the security patches provided by Adobe.
Which versions of Adobe Reader are affected by CVE-2011-0592?
CVE-2011-0592 affects Adobe Reader and Acrobat versions prior to 10.0.1, 9.4.2, and 8.2.6.
Can CVE-2011-0592 be exploited without user interaction?
Yes, CVE-2011-0592 can be exploited by an adversary through a crafted file, which does not require user interaction for execution.
What types of systems are vulnerable to CVE-2011-0592?
CVE-2011-0592 affects Windows and Mac OS X systems running affected versions of Adobe Reader and Acrobat.