|
Arr1val has discovered two vulnerabilities in Adobe Reader, which can be exploited by malicious people to potentially compromise a user's system. 1) An error when processing calls to the "getAnnots()" JavaScript method can be exploited to corrupt memory via a specially crafted PDF file. 2) An error when processing calls to the "customDictionaryOpen()" JavaScript method can be exploited to corrupt memory via a specially crafted PDF file. Successful exploitation may allow execution of arbitrary code. The vulnerabilities are confirmed in version 9.1 for Linux. Other versions may also be affected.
|