Null pointer dereference in Adobe Reader and Adobe Acrobat - CVE-2009-3957
Published: December 19, 2016 / Updated: January 9, 2017
Vulnerability identifier: #VU1396
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2009-3957
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS conditions on the target system.
The weakness exists due to NULL pointer dereference. A remote attacker can trigger the application to crash.
Successful exploitation of the vulnerability results in denial of service of the vulnerable application.
The weakness exists due to NULL pointer dereference. A remote attacker can trigger the application to crash.
Successful exploitation of the vulnerability results in denial of service of the vulnerable application.
Affected software
Adobe Reader
Adobe Acrobat
Adobe Acrobat
How to mitigate CVE-2009-3957
Update Adobe Reader and Adobe Acrobat 8.1.7 or earlier to version 8.2.
Update Adobe Reader and Adobe Acrobat 9.2 or earlier to version 9.3.
http://get.adobe.com/reader
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=158&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=112&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Macintosh
Update Adobe Reader and Adobe Acrobat 9.2 or earlier to version 9.3.
http://get.adobe.com/reader
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=158&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=112&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Macintosh