CVE Vulnerabilities

CVE-2009-3955

Published: Jan 13, 2010 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted JPC_MS_RGN marker in the Jp2c stream of a JpxDecode encoded data stream, which triggers an integer sign extension that bypasses a sanity check, leading to memory corruption.

Affected Software

NameVendorStart VersionEnd Version
AcrobatAdobe*9.2 (including)
AcrobatAdobe3.0 (including)3.0 (including)
AcrobatAdobe3.1 (including)3.1 (including)
AcrobatAdobe4.0 (including)4.0 (including)
AcrobatAdobe4.0.5 (including)4.0.5 (including)
AcrobatAdobe4.0.5a (including)4.0.5a (including)
AcrobatAdobe4.0.5c (including)4.0.5c (including)
AcrobatAdobe5.0 (including)5.0 (including)
AcrobatAdobe5.0.5 (including)5.0.5 (including)
AcrobatAdobe5.0.6 (including)5.0.6 (including)
AcrobatAdobe5.0.10 (including)5.0.10 (including)
AcrobatAdobe6.0 (including)6.0 (including)
AcrobatAdobe6.0.1 (including)6.0.1 (including)
AcrobatAdobe6.0.2 (including)6.0.2 (including)
AcrobatAdobe6.0.3 (including)6.0.3 (including)
AcrobatAdobe6.0.4 (including)6.0.4 (including)
AcrobatAdobe6.0.5 (including)6.0.5 (including)
AcrobatAdobe6.0.6 (including)6.0.6 (including)
AcrobatAdobe7.0 (including)7.0 (including)
AcrobatAdobe7.0.1 (including)7.0.1 (including)
AcrobatAdobe7.0.2 (including)7.0.2 (including)
AcrobatAdobe7.0.3 (including)7.0.3 (including)
AcrobatAdobe7.0.4 (including)7.0.4 (including)
AcrobatAdobe7.0.5 (including)7.0.5 (including)
AcrobatAdobe7.0.6 (including)7.0.6 (including)
AcrobatAdobe7.0.7 (including)7.0.7 (including)
AcrobatAdobe7.0.8 (including)7.0.8 (including)
AcrobatAdobe7.0.9 (including)7.0.9 (including)
AcrobatAdobe7.1.0 (including)7.1.0 (including)
AcrobatAdobe7.1.1 (including)7.1.1 (including)
AcrobatAdobe7.1.2 (including)7.1.2 (including)
AcrobatAdobe7.1.3 (including)7.1.3 (including)
AcrobatAdobe7.1.4 (including)7.1.4 (including)
AcrobatAdobe8.0 (including)8.0 (including)
AcrobatAdobe8.1 (including)8.1 (including)
AcrobatAdobe8.1.1 (including)8.1.1 (including)
AcrobatAdobe8.1.2 (including)8.1.2 (including)
AcrobatAdobe8.1.3 (including)8.1.3 (including)
AcrobatAdobe8.1.4 (including)8.1.4 (including)
AcrobatAdobe8.1.5 (including)8.1.5 (including)
AcrobatAdobe8.1.6 (including)8.1.6 (including)
AcrobatAdobe8.1.7 (including)8.1.7 (including)
AcrobatAdobe9.0 (including)9.0 (including)
AcrobatAdobe9.1 (including)9.1 (including)
AcrobatAdobe9.1.1 (including)9.1.1 (including)
AcrobatAdobe9.1.2 (including)9.1.2 (including)
AcrobatAdobe9.1.3 (including)9.1.3 (including)
Extras for RHEL 3RedHatacroread-0:9.3-3*
Extras for RHEL 4RedHatacroread-0:9.3-1.el4*
Supplementary for Red Hat Enterprise Linux 5RedHatacroread-0:9.3-1.el5*

References