Intrusion Prevention

Adobe.Reader.CFF.Encoding.Handling.Heap.Overflow

Description

This indicates an attack attempt against a heap-overflow vulnerability in Adobe Reader and Acrobat.
This vulnerability is caused by an error when the vulnerable software handles a PDF file that has malformed CFF font. A remote attacker may exploit this to execute arbitrary code.

Affected Products

Adobe Reader 9.3.1 and earlier versions for Windows, Macintosh, and UNIX
Adobe Acrobat 9.3.1 and earlier versions for Windows and Macintosh

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the latest update from the vendor.
http://www.adobe.com/support/security/bulletins/apsb10-09.html

CVE References

CVE-2010-1241 CVE-2010-0200