Home / vulnerabilitiesPDF  

Zero Day Initiative Advisory 11-296

Posted on 26 October 2011
Source : packetstormsecurity.org Link

 

Zero Day Initiative Advisory 11-296 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the Adobe Image parsing library. When Adobe Reader tries to parse an malformed .BMP image containing Run Length Encoded data it fails to perform sufficient boundary checks on the data. The effect can be a heap buffer overflow resulting in remote code execution under the context of the current user.

 

TOP