#VU3509 Improper input validation in Adobe Reader and Adobe Acrobat - CVE-2010-3657
Published: January 5, 2017
Vulnerability identifier: #VU3509
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2010-3657
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Adobe Reader
Adobe Acrobat
Adobe Reader
Adobe Acrobat
Software vendor:
Adobe
Adobe
Description
The vulnerability allows a remote attacker to cause denial of service conditions.
The vulnerability exists due to improper input validation error when processing PDF documents. A remote attacker can create a specially crafted PDF document, trick the victim into opening it and trigger application crash.
Remediation
Install the latest version from vendor's website. The vulnerability is fixed in Adobe Reader and Acrobat 9.4 and 8.2.5.