Security Advisory

CVE-2009-3955

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2010-01-13 19:00:00
Last updated 2024-08-07 06:45:50
Assigner adobe
CVSS score not scored
State PUBLISHED

Description

Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted JPC_MS_RGN marker in the Jp2c stream of a JpxDecode encoded data stream, which triggers an integer sign extension that bypasses a sanity check, leading to memory corruption.