// For flags

CVE-2009-1855

Adobe Reader U3D RHAdobeMeta Stack Overflow Vulnerability

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Stack-based buffer overflow in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to execute arbitrary code via a PDF file containing a malformed U3D model file with a crafted extension block.

Un desbordamiento de búfer en la región stack de la memoria en Reader versión 7 y Acrobat versiones 7 anteriores a 7.1.3 de Adobe, Reader versión 8 y Acrobat versiones 8 anteriores a 8.1.6 y Reader versión 9 y Acrobat versiones 9 anteriores a 9.1.2 de Adobe, podría permitir a los atacantes ejecutar código arbitrario por medio de un archivo PDF que contiene un archivo de modelo U3D malformado con un bloque de extensión diseñado.

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Acrobat and Adobe Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious web address or open a malicious file.
The specific flaw exists when parsing malformed U3D model files contained in a PDF. When a specially crafted extension block of a model is processed, insufficient bounds checking is done before a call to wcsncpy(). Because of this a stack overflow can occur resulting in reliable code execution. Proper exploitation of this vulnerability will result in system compromise under the credentials of the currently logged in user.

*Credits: Anonymous
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-06-01 CVE Reserved
  • 2009-06-10 CVE Published
  • 2024-04-10 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0
Search vendor "Adobe" for product "Acrobat" and version "7.0"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0
Search vendor "Adobe" for product "Acrobat" and version "7.0"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0
Search vendor "Adobe" for product "Acrobat" and version "7.0"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.1
Search vendor "Adobe" for product "Acrobat" and version "7.0.1"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.1
Search vendor "Adobe" for product "Acrobat" and version "7.0.1"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.1
Search vendor "Adobe" for product "Acrobat" and version "7.0.1"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.2
Search vendor "Adobe" for product "Acrobat" and version "7.0.2"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.2
Search vendor "Adobe" for product "Acrobat" and version "7.0.2"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.2
Search vendor "Adobe" for product "Acrobat" and version "7.0.2"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.3
Search vendor "Adobe" for product "Acrobat" and version "7.0.3"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.3
Search vendor "Adobe" for product "Acrobat" and version "7.0.3"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.3
Search vendor "Adobe" for product "Acrobat" and version "7.0.3"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.4
Search vendor "Adobe" for product "Acrobat" and version "7.0.4"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.4
Search vendor "Adobe" for product "Acrobat" and version "7.0.4"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.4
Search vendor "Adobe" for product "Acrobat" and version "7.0.4"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.5
Search vendor "Adobe" for product "Acrobat" and version "7.0.5"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.5
Search vendor "Adobe" for product "Acrobat" and version "7.0.5"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.5
Search vendor "Adobe" for product "Acrobat" and version "7.0.5"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.6
Search vendor "Adobe" for product "Acrobat" and version "7.0.6"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.6
Search vendor "Adobe" for product "Acrobat" and version "7.0.6"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.6
Search vendor "Adobe" for product "Acrobat" and version "7.0.6"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.7
Search vendor "Adobe" for product "Acrobat" and version "7.0.7"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.7
Search vendor "Adobe" for product "Acrobat" and version "7.0.7"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.7
Search vendor "Adobe" for product "Acrobat" and version "7.0.7"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.8
Search vendor "Adobe" for product "Acrobat" and version "7.0.8"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.8
Search vendor "Adobe" for product "Acrobat" and version "7.0.8"
elements
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.8
Search vendor "Adobe" for product "Acrobat" and version "7.0.8"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.8
Search vendor "Adobe" for product "Acrobat" and version "7.0.8"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.9
Search vendor "Adobe" for product "Acrobat" and version "7.0.9"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.0.9
Search vendor "Adobe" for product "Acrobat" and version "7.0.9"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.1
Search vendor "Adobe" for product "Acrobat" and version "7.1"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.1
Search vendor "Adobe" for product "Acrobat" and version "7.1"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.1
Search vendor "Adobe" for product "Acrobat" and version "7.1"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.1.0
Search vendor "Adobe" for product "Acrobat" and version "7.1.0"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.1.1
Search vendor "Adobe" for product "Acrobat" and version "7.1.1"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
7.1.1
Search vendor "Adobe" for product "Acrobat" and version "7.1.1"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.0
Search vendor "Adobe" for product "Acrobat" and version "8.0"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.0
Search vendor "Adobe" for product "Acrobat" and version "8.0"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.0
Search vendor "Adobe" for product "Acrobat" and version "8.0"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1
Search vendor "Adobe" for product "Acrobat" and version "8.1"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1
Search vendor "Adobe" for product "Acrobat" and version "8.1"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1.1
Search vendor "Adobe" for product "Acrobat" and version "8.1.1"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1.1
Search vendor "Adobe" for product "Acrobat" and version "8.1.1"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1.1
Search vendor "Adobe" for product "Acrobat" and version "8.1.1"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1.2
Search vendor "Adobe" for product "Acrobat" and version "8.1.2"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1.2
Search vendor "Adobe" for product "Acrobat" and version "8.1.2"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1.2
Search vendor "Adobe" for product "Acrobat" and version "8.1.2"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1.2
Search vendor "Adobe" for product "Acrobat" and version "8.1.2"
security_update, professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1.3
Search vendor "Adobe" for product "Acrobat" and version "8.1.3"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1.3
Search vendor "Adobe" for product "Acrobat" and version "8.1.3"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1.3
Search vendor "Adobe" for product "Acrobat" and version "8.1.3"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1.4
Search vendor "Adobe" for product "Acrobat" and version "8.1.4"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1.4
Search vendor "Adobe" for product "Acrobat" and version "8.1.4"
professional
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
8.1.4
Search vendor "Adobe" for product "Acrobat" and version "8.1.4"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
9
Search vendor "Adobe" for product "Acrobat" and version "9"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
9.0
Search vendor "Adobe" for product "Acrobat" and version "9.0"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
9.0
Search vendor "Adobe" for product "Acrobat" and version "9.0"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
9.0.0
Search vendor "Adobe" for product "Acrobat" and version "9.0.0"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
9.1
Search vendor "Adobe" for product "Acrobat" and version "9.1"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat
Search vendor "Adobe" for product "Acrobat"
9.1
Search vendor "Adobe" for product "Acrobat" and version "9.1"
standard
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
7.0
Search vendor "Adobe" for product "Acrobat Reader" and version "7.0"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
7.0.1
Search vendor "Adobe" for product "Acrobat Reader" and version "7.0.1"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
7.0.2
Search vendor "Adobe" for product "Acrobat Reader" and version "7.0.2"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
7.0.3
Search vendor "Adobe" for product "Acrobat Reader" and version "7.0.3"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
7.0.4
Search vendor "Adobe" for product "Acrobat Reader" and version "7.0.4"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
7.0.5
Search vendor "Adobe" for product "Acrobat Reader" and version "7.0.5"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
7.0.6
Search vendor "Adobe" for product "Acrobat Reader" and version "7.0.6"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
7.0.7
Search vendor "Adobe" for product "Acrobat Reader" and version "7.0.7"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
7.0.8
Search vendor "Adobe" for product "Acrobat Reader" and version "7.0.8"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
7.0.9
Search vendor "Adobe" for product "Acrobat Reader" and version "7.0.9"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
7.1
Search vendor "Adobe" for product "Acrobat Reader" and version "7.1"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
7.1.1
Search vendor "Adobe" for product "Acrobat Reader" and version "7.1.1"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
8.0
Search vendor "Adobe" for product "Acrobat Reader" and version "8.0"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
8.1
Search vendor "Adobe" for product "Acrobat Reader" and version "8.1"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
8.1.1
Search vendor "Adobe" for product "Acrobat Reader" and version "8.1.1"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
8.1.2
Search vendor "Adobe" for product "Acrobat Reader" and version "8.1.2"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
8.1.2
Search vendor "Adobe" for product "Acrobat Reader" and version "8.1.2"
security_update
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
8.1.3
Search vendor "Adobe" for product "Acrobat Reader" and version "8.1.3"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
8.1.4
Search vendor "Adobe" for product "Acrobat Reader" and version "8.1.4"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
8.1.5
Search vendor "Adobe" for product "Acrobat Reader" and version "8.1.5"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
9
Search vendor "Adobe" for product "Acrobat Reader" and version "9"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
9.1
Search vendor "Adobe" for product "Acrobat Reader" and version "9.1"
-
Affected
Adobe
Search vendor "Adobe"
Acrobat Reader
Search vendor "Adobe" for product "Acrobat Reader"
9.1.1
Search vendor "Adobe" for product "Acrobat Reader" and version "9.1.1"
-
Affected