CVE-2009-4324

EUVD-2009-4292
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
adobeacrobat
8.0 ≤
𝑥
< 8.2
adobeacrobat
9.0 ≤
𝑥
< 9.3
adobeacrobat_reader
8.0 ≤
𝑥
< 8.2
adobeacrobat_reader
9.0 ≤
𝑥
< 9.3
opensuseopensuse
11.1
opensuseopensuse
11.2
suselinux_enterprise
10.0:sp2
suselinux_enterprise
10.0:sp3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
acroread
dapper
ignored
hardy
Fixed 9.3.1-1hardy2
released
intrepid
Fixed 9.3.1-1intrepid1
released
jaunty
Fixed 9.3.1-1jaunty1
released
karmic
Fixed 9.3.1-1karmic1
released
References