CVE-2011-0596: Input Validation
The Bitmap parsing component in 2d.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via an image with crafted (1) height and (2) width values for an RLE8 compressed bitmap, which triggers a heap-based buffer overflow, a different vulnerability than CVE-2011-0598, CVE-2011-0599, and CVE-2011-0602.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0596?
CVE-2011-0596 is classified as a critical vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2011-0596?
To fix CVE-2011-0596, update Adobe Reader and Acrobat to version 10.0.1 or later, 9.4.2 or later, or 8.2.6 or later.
What software is affected by CVE-2011-0596?
CVE-2011-0596 affects Adobe Reader and Acrobat versions 10.x prior to 10.0.1, 9.x prior to 9.4.2, and 8.x prior to 8.2.6.
Can CVE-2011-0596 be exploited remotely?
Yes, CVE-2011-0596 can be exploited remotely through a specially crafted image containing malicious bitmap data.
What platform is impacted by CVE-2011-0596?
CVE-2011-0596 impacts both Windows and Mac OS X platforms running vulnerable versions of Adobe Reader and Acrobat.