First published: Thu Sep 15 2011(Updated: )
Buffer overflow in the U3D TIFF Resource in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader Notification Manager | =8.1.6 | |
Adobe Acrobat Reader Notification Manager | =10.0 | |
Adobe Acrobat Reader Notification Manager | =8.2.3 | |
Adobe Acrobat Reader Notification Manager | =9.4.3 | |
Adobe Acrobat Reader Notification Manager | =8.2.6 | |
Adobe Acrobat Reader Notification Manager | =8.2 | |
Adobe Acrobat Reader Notification Manager | =10.0.3 | |
Adobe Acrobat Reader Notification Manager | =9.2 | |
Adobe Acrobat Reader Notification Manager | =8.2.2 | |
Adobe Acrobat Reader Notification Manager | =9.1 | |
Adobe Acrobat Reader Notification Manager | =8.2.4 | |
Adobe Acrobat Reader Notification Manager | =9.1.3 | |
Adobe Acrobat Reader Notification Manager | =8.0 | |
Adobe Acrobat Reader Notification Manager | =9.1.2 | |
Adobe Acrobat Reader Notification Manager | =8.1.5 | |
Adobe Acrobat Reader Notification Manager | =9.3.3 | |
Adobe Acrobat Reader Notification Manager | =9.4.2 | |
Adobe Acrobat Reader Notification Manager | =9.1.1 | |
Adobe Acrobat Reader Notification Manager | =8.2.1 | |
Adobe Acrobat Reader Notification Manager | =8.3 | |
Adobe Acrobat Reader Notification Manager | =8.1.7 | |
Adobe Acrobat Reader Notification Manager | =8.1.4 | |
Adobe Acrobat Reader Notification Manager | =9.3.4 | |
Adobe Acrobat Reader Notification Manager | =8.1.2 | |
Adobe Acrobat Reader Notification Manager | =9.3 | |
Adobe Acrobat Reader Notification Manager | =9.0 | |
Adobe Acrobat Reader Notification Manager | =9.4 | |
Adobe Acrobat Reader Notification Manager | =8.1.1 | |
Adobe Acrobat Reader Notification Manager | =9.3.2 | |
Adobe Acrobat Reader Notification Manager | =8.1 | |
Adobe Acrobat Reader Notification Manager | =10.0.1 | |
Adobe Acrobat Reader Notification Manager | =8.1.3 | |
Adobe Acrobat Reader Notification Manager | =9.4.4 | |
Adobe Acrobat Reader Notification Manager | =9.3.1 | |
Adobe Acrobat Reader Notification Manager | =10.0.2 | |
Adobe Acrobat Reader Notification Manager | =9.4.1 | |
Adobe Acrobat Reader | =8.0 | |
Adobe Acrobat Reader | =8.1.7 | |
Adobe Acrobat Reader | =8.2.1 | |
Adobe Acrobat Reader | =9.3.3 | |
Adobe Acrobat Reader | =10.1 | |
Adobe Acrobat Reader | =8.1.2 | |
Adobe Acrobat Reader | =9.4.2 | |
Adobe Acrobat Reader | =9.2 | |
Adobe Acrobat Reader | =9.1 | |
Adobe Acrobat Reader | =10.0 | |
Adobe Acrobat Reader | =9.4.3 | |
Adobe Acrobat Reader | =8.2.4 | |
Adobe Acrobat Reader | =8.1.1 | |
Adobe Acrobat Reader | =10.0.3 | |
Adobe Acrobat Reader | =9.4.4 | |
Adobe Acrobat Reader | =8.2.3 | |
Adobe Acrobat Reader | =8.2 | |
Adobe Acrobat Reader | =8.1 | |
Adobe Acrobat Reader | =9.0 | |
Adobe Acrobat Reader | =9.3.4 | |
Adobe Acrobat Reader | =8.2.2 | |
Adobe Acrobat Reader | =9.4.1 | |
Adobe Acrobat Reader | =9.3.2 | |
Adobe Acrobat Reader | =9.1.1 | |
Adobe Acrobat Reader | =8.1.5 | |
Adobe Acrobat Reader | =8.1.4 | |
Adobe Acrobat Reader | =9.3.1 | |
Adobe Acrobat Reader | =8.2.6 | |
Adobe Acrobat Reader | =9.1.2 | |
Adobe Acrobat Reader | =10.0.2 | |
Adobe Acrobat Reader | =8.1.6 | |
Adobe Acrobat Reader | =10.0.1 | |
Adobe Acrobat Reader | =9.1.3 | |
Adobe Acrobat Reader | =9.4.5 | |
Adobe Acrobat Reader | =8.2.5 | |
Adobe Acrobat Reader | =8.1.3 | |
Adobe Acrobat Reader | =9.4 | |
Adobe Acrobat Reader | =9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2432 is classified as a critical vulnerability that can allow attackers to execute arbitrary code.
To resolve CVE-2011-2432, you should update to Adobe Reader and Acrobat versions 8.3.1, 9.4.6, or 10.1.1 or later.
CVE-2011-2432 affects Adobe Reader versions 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1.
CVE-2011-2432 can be exploited through a buffer overflow vulnerability, potentially allowing remote code execution.
The best workaround for CVE-2011-2432 is to avoid opening untrusted PDF files until you can apply the necessary updates.