CVE ID | CVE-2011-2432 |
CVSS SCORE | 7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P |
AFFECTED VENDORS |
Adobe |
AFFECTED PRODUCTS |
Reader |
VULNERABILITY DETAILS |
The specific flaw exists within because Adobe Reader X includes an old version of libtiff. Adobe can be tricked in using this library by parsing a specially crafted PDF file containing U3D data. Due to the old version of libtiff Adobe Reader is vulnerable to the issue described in CVE-2006-3459 which can be leveraged to execute remote code under the context of the user running the application. |
ADDITIONAL DETAILS |
Adobe has issued an update to correct this vulnerability. More details can be found at:
http://www.adobe.com/support/security/bulletins/apsb11-24.html |
DISCLOSURE TIMELINE |
|
CREDIT | binaryproof |