52073 : Adobe Reader / Acrobat Document Handling JBIG2 Compression Overflow
Printer | http://osvdb.org/52073 | Email This | Edit Vulnerability

Views This Week

30

Views All Time

1574

Info

Last Modified

9 months ago

Percent Complete

90%

Disclosure

Feb 19, 2009

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Keywords

6816953

Description

A buffer overflow exists in Acrobat and Acrobat Reader. They fail to validate PDF files which use JBIG2 compression routines resulting in a buffer overflow. With a specially crafted file, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local / Remote, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public, Exploit Rumored
Disclosure: Discovered in the Wild

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

Adobe Systems Incorporated
Watch-list
Acrobat
Watch-list
9.0
Acrobat Reader
Watch-list
9.0

References

Tools & Filters

Snort

15354 15355 15356 15357 15358 15359 15360 15494 15495 15496 15497

Credit

Unknown or Incomplete

CVSSv2 Score

CVSSv2 Base Score = 9.3
Source: nvd.nist.gov | Generated: 2009-02-23 | Disagree?

Access_vector_2 Access_complexity_1 Authentication_2 Confidentiality_impact_2 Integrity_impact_2 Availability_impact_2

Blogs

This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.

2009/04/20 10:30:31 | Snoop Security Magazine No#2 is out[Persian]

from: Snoop Security Researching Community

Hi folks, I’m here to proudly present Snoop Security No#2 to you. You can grab a copy from below address and read it: http://snoopmag ... - Part 2 - Surf Jacking - Analysis of CVE-2009-0658 - Introduction to Honeypots - Using Dynamic IP

2009/04/13 07:00:00 | Sun Alert 256788 Multiple Security Vulnerabilities in Adobe Reader for Solaris 10 May Allow Execution of Arbitrary Code or Cause a Denial of Service (DoS) (Adobe Security Bulletin APSB09-04)

from: Security

Product: Solaris 10 Operating System Multiple security vulnerabilities in Adobe Reader 9 ... APSB09-04 at http://www.adobe.com/support/security/bulletins/apsb09-04.html CVE-2009-0658 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0658 CVE-2009-0193 at http://cve.mitre.org/cgi

2009/03/24 21:34:00 | Adobe Reader and Acrobat - Critical Security Updates

from: MSMVPS.COM

These updates should be applied promptly, as there have been PDF based attacks in the wild involving JavaScript vulnerabilities. http://www.adobe ... . There are reports that one of these issues is being exploited (CVE-2009-0658). Adobe recommends

2009/03/23 01:12:13 | Critical Adobe Security bulletin - Security Updates available for Adobe Reader and Acrobat

from: TITSSN's Main Blogs Suite

http://www.adobe.com/support/security/bulletins/apsb09-04 ... date: March 18, 2009 Vulnerability identifier: APSB09-04 CVE number: CVE-2009-0658 ... . There are reports that one of these issues is being exploited (CVE-2009-0658). Adobe recommends

2009/03/18 22:49:00 | Security Updates for Adobe Reader and Adobe Vulnerabilities

from: Security Garden

This is a very important update. Don't wait, update to Adobe Reader 9.1 now. Available here: http://get.adobe.com/reader/ . Release date: March 18, 2009 Vulnerability identifier: APSB09-04 CVE number: CVE-2009-0658 ... . There are reports that one of these issues is being exploited (CVE-2009-0658). Adobe recommends users

2009/03/19 09:56:00 | Adobe PDFs executing malicious code

from: paris-photo

Trend Micro has warned against buffer overflow vulnerability in versions 9.0 ... Vulnerability CVE-2009-0658 - an array indexing error when processing a malformed JBIG2 stream

2009/03/18 21:58:06 | Adobe Security Updates For Compromised Acrobat and Reader Released

from: Infosecurity.US

Adobe Systems Inc. (NasdaqGS: ADBE ) has released a security announcement detailing specific updates for previously reported Critical and ... : March 18, 2009 Vulnerability identifier: APSB09-04 CVE number: CVE-2009-0658, CVE-2009-0927 ... . There are reports that one of these issues is being exploited (CVE-2009-0658). Adobe recommends users

2009/03/16 16:08:00 | Adobe Programs are Vulnerable to Trojan Attacks Says Trend Micro

from: Gadget Blog 7

Trend Micro, an international content security provider, has warned users against a buffer overflow vulnerability in versions 9.0 ... TROJ_PIDIEF.IN takes advantage of Adobe Vulnerability CVE-2009-0658 - an array indexing error

2009/03/18 20:16:21 | Adobe Security Bulletin APSB09-04 - Security Updates available for Adobe Reader and Acrobat

from: Donna's SecurityFlash

Critical vulnerabilities have been identified in Adobe Reader 9 and Acrobat 9 and earlier versions ... exploited (CVE-2009-0658). Adobe recommends users of Adobe Reader and Acrobat 9 update to Adobe Reader ... date: March 18, 2009 Vulnerability identifier: APSB09-04 CVE number: CVE-2009-0658

2009/03/18 20:16:00 | Security Updates available for Adobe Reader and Acrobat

from: MSMVPS.COM

Summary Critical vulnerabilities have been identified in Adobe Reader 9 and Acrobat 9 and earlier versions ... exploited (CVE-2009-0658). Adobe recommends users of Adobe Reader and Acrobat 9 update to Adobe Reader

2009/03/17 09:51:32 | Adobe Programs are Vulnerable to Trojan Attacks Says Trend Micro

from: SoftWare News - netfordownload.com

Adobe Programs are Vulnerable to Trojan Attacks Says Trend MicroTuesday, March 17, 2009 4:51 Posted in category Adobe, Internet Explorer, ... the process: “For example, the Trojan TROJ_PIDIEF.IN takes advantage of Adobe Vulnerability CVE-2009-0658

2009/03/12 16:52:57 | Analysis of CVE-2009-0658 (Adobe Reader 0day)

from: SecureWorks Research Blog

Bow here again. It has been a while since we posted a binary analysis on our blog, so I figured we would post one for a vuln that has been getting a lot of hoopla the past few weeks :)

2009/02/25 01:46:26 | Adobe Reader and Acrobat Issue update

from: Adobe Product Security Incident Response Team (PSIRT)

This is an update on the Adobe Reader and Acrobat issue (CVE-2009-0658) discussed in Security Advisory APSA09-01 . As mentioned previously, Adobe currently plans to make available an update

2009/02/23 22:47:30 | Adobe Vulnerability on the Loose?

from: Optimal Security

An Adobe vulnerability CVE-2009-0658 is actively being used in the wild as “Trojan.Pidief.E.” in targeted attacks and Adobe does currently not plan to release a patch until March 11th at best

2009/03/11 11:22:18 | Adobe finally patches zero-day exploit

from: Browse News | TechRadar UK

Adobe has patched the zero-day exploit in its PDF readers, including Acrobat, that has given hackers an exploit for two months. Adobe Reader 9 ... (CVE-2009-0658), including the 'no-click' variant of the vulnerability," blogged Adobe's David Lenoe

2009/03/11 06:50:20 | Adobe Reader and Acrobat 9.1 update available.

from: Blog Vincenzo Di Russo's [MVP IE] Blog -

Adobe Reader and Acrobat 9.1 update available "Today, we posted the Adobe Reader 9.1 and Acrobat 9.1 update, which resolves the recent JBIG2 security issue (CVE-2009-0658), including the ‘no-click’ variant of the vulnerability. We encourage all Adobe Reader users to download and install the free

2009/03/10 20:29:45 | Adobe Reader and Acrobat 9.1 update available

from: Adobe Product Security Incident Response Team (PSIRT)

Today, we posted the Adobe Reader 9.1 and Acrobat 9.1 update, which resolves the recent JBIG2 security issue (CVE-2009-0658), including the ‘no-click’ variant of the vulnerability. We encourage

2009/02/27 18:27:21 | February Threatscape - Exploits, Conficker, Waledac and Sexy View

from: Fortinet FortiGuard Blog

February Threatscape - Exploits, Conficker, Waledac and Sexy View by Derek Manky February 27, 2009 at 10: ... and CVE-2009-0658) affecting MS Excel (XLS) and Adobe Reader (PDF) have since been disclosed. Given

2009/02/25 02:18:21 | Adobe Reader and Acrobat Issue update

from: Adobe Blogs

This is an update on the Adobe Reader and Acrobat issue (CVE-2009-0658) discussed in Security Advisory APSA09-01. As mentioned previously, Adobe currently plans to make available an update for Adobe

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2010 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use