Vulnerability Description
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Acrobat | >= 8.0, < 8.2 |
| Adobe | Acrobat Reader | >= 8.0, < 8.2 |
| Apple | Mac Os X | - |
| Microsoft | Windows | - |
| Suse | Linux Enterprise Debuginfo | 11 |
| Opensuse | Opensuse | 11.1 |
| Suse | Linux Enterprise | 10.0 |
Related Weaknesses (CWE)
References
- http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.htmlBroken LinkVendor Advisory
- http://contagiodump.blogspot.com/2009/12/virustotal-httpwww.htmlExploitThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.htmlMailing ListThird Party Advisory
- http://osvdb.org/60980Broken Link
- http://secunia.com/advisories/37690Broken LinkVendor Advisory
- http://secunia.com/advisories/38138Broken LinkVendor Advisory
- http://secunia.com/advisories/38215Broken LinkVendor Advisory
- http://www.adobe.com/support/security/advisories/apsa09-07.htmlVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb10-02.htmlNot Applicable
- http://www.kb.cert.org/vuls/id/508357Third Party AdvisoryUS Government Resource
- http://www.metasploit.com/redmine/projects/framework/repository/revisions/7881/eBroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0060.htmlBroken Link
- http://www.securityfocus.com/bid/37331Broken LinkThird Party AdvisoryVDB Entry
- http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214Broken Link
- http://www.symantec.com/connect/blogs/zero-day-xmas-presentBroken Link
FAQ
What is CVE-2009-4324?
CVE-2009-4324 is a vulnerability with a CVSS score of 7.8 (HIGH). Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to exec...
How severe is CVE-2009-4324?
CVE-2009-4324 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-4324?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Acrobat, Adobe Acrobat Reader, Apple Mac Os X, Microsoft Windows, Suse Linux Enterprise Debuginfo.