CVE-2011-0599: Input Validation
The Bitmap parsing component in rt3d.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a crafted image that causes an invalid pointer calculation related to 4/8-bit RLE compression, a different vulnerability than CVE-2011-0596, CVE-2011-0598, and CVE-2011-0602.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0599?
CVE-2011-0599 is classified with a critical severity rating due to the potential for remote code execution.
How do I fix CVE-2011-0599?
To fix CVE-2011-0599, update Adobe Reader and Acrobat to version 10.0.1 or later, 9.4.2 or later, or 8.2.6 or later.
Which versions of Adobe Reader are affected by CVE-2011-0599?
CVE-2011-0599 affects Adobe Reader versions 8.x before 8.2.6, 9.x before 9.4.2, and 10.x before 10.0.1.
What types of attacks are possible due to CVE-2011-0599?
CVE-2011-0599 allows remote attackers to execute arbitrary code by exploiting an invalid pointer calculation in the Bitmap parsing component.
Is CVE-2011-0599 exploitable on both Windows and Mac OS X?
Yes, CVE-2011-0599 is exploitable on both Windows and Mac OS X platforms.