HomeCommunitySecurity Blog

Security Blog

 

Threat Lab Report: Troj.Exploit.W32.PDF-URI.o

Posted By Netgear Threat Lab at 7:00 PM, January 24, 2010

Troj.Exploit.W32.PDF-URI.o

Behavior:9
Description:Adobe Acrobat and Reader are prone to a remote code-execution vulnerability CVE-2009-0927.
When supplying a specially crafted argument to the getIcon() method of a Collab object, proper bounds checking is not performed resulting in a stack overflow. By persuading a victim to open a specially-crafted PDF file, a remote attacker could exploit this vulnerability to overflow a buffer and execute arbitrary code on the system with the privileges of the victim.
Affected Versions: Reader and Acrobat 7.1 and prior
Reader and Acrobat 8.1.2 and prior
Reader and Acrobat 9

Posted by: Netgear Threat Lab at 7:00 PM
Categories: Malware , Netgear Threat Lab

No TrackBacks

TrackBack URL: http://prosecure.netgear.com/cgi-bin/mt/mt-tb.cgi/69

Comments