CVE-2010-2883

Scores

EPSS

0.932high93.2%
0%20%40%60%80%100%

Percentile: 93.2%

CVSS

7.3high3.x
0246810

CVSS Score: 7.3/10

All CVSS Scores

CVSS 3.x
7.3

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVSS 2.0
6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Description

Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvdredhat

CWEs

CWE-121CWE-787

Related Vulnerabilities

Exploits

Exploit ID: 16494

Source: exploitdb

URL: https://www.exploit-db.com/exploits/16494

Exploit ID: 16619

Source: exploitdb

URL: https://www.exploit-db.com/exploits/16619

Exploit ID: CVE-2010-2883

Source: github-poc

URL: https://github.com/avielzecharia/CVE-2010-2883

Recommendations

Source: nvd

All Adobe Reader users should upgrade to the latest stable version:

# emerge –sync
# emerge –ask –oneshot –verbose “>=app-text/acroread-9.4.1”

URL: http://security.gentoo.org/glsa/glsa-201101-08.xml

Vulnerable Software (4)

Type: Configuration

Product: acroread

Operating System: rhel

Trait:
{  "fixed": "9.4.0-1.el4"}

Source: redhat

Type: Configuration

Product: acroread

Operating System: rhel

Trait:
{  "fixed": "9.4.0-1.el5"}

Source: redhat

Type: Configuration

Vendor: *

Product: acrobat

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*",          "versionEndExcluding": "8.2.5",          "versionStartIncluding": "8....

Source: nvd

Type: Configuration

Vendor: *

Product: acrobat_reader

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*",          "versionEndExcluding": "8.2.5",          "versionStartIncludin...

Source: nvd

End of list