SUSE-SA:2010:008Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html CVE-2009-3958
Adobe GetPlus get_atlcom 1.6.2.48 - ActiveX Remote Execution
Record summary
CVE-2009-3958 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow remote attackers to execute arbitrary code via unspecified initialization parameters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAdobe GetPlus get_atlcom 1.6.2.48 - ActiveX Remote ExecutionExploitDB exploitby superliNot analyzed1 file
References
10adobe.comConfirmation
http://www.adobe.com/support/security/bulletins/apsb10-02.html VU#773545Third-party advisory
http://www.kb.cert.org/vuls/id/773545 37759vdb entry
http://www.securityfocus.com/bid/37759 1023446vdb entry
http://www.securitytracker.com/id?1023446 TA10-013AThird-party advisory
http://www.us-cert.gov/cas/techalerts/TA10-013A.html ADV-2010-0103vdb entry
http://www.vupen.com/english/advisories/2010/0103 acrobat-reader-download-manager-bo(55556)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/55556 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-3958 oval:org.mitre.oval:def:8455vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8455