what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

iDEFENSE Security Advisory 2009-06-09.3

iDEFENSE Security Advisory 2009-06-09.3
Posted Jun 11, 2009
Authored by iDefense Labs, Ryan Smith, Jun Mao | Site idefense.com

iDefense Security Advisory 06.09.09 - Remote exploitation of an integer overflow vulnerability in multiple versions of Adobe Systems Inc's Reader and Acrobat PDF reader and processor could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability occurs when parsing a FlateDecode filter inside a PDF file. FlateDecode is a filter for data compressed with zlib deflate compression method. Several parameters can be specified for the FlateDecode filter. Those values are used in an arithmetic operation that calculates the number of bytes to allocate for a heap buffer. This calculation can overflow, which results in an undersized heap buffer being allocated. This buffer is then overflowed with data decompressed from the FlateDecode stream. This leads to a heap-based buffer overflow that can result in arbitrary code execution. Acrobat Reader and Acrobat Professional versions 7.1.0, 8.1.3, 9.0.0 and prior versions are vulnerable.

tags | advisory, remote, overflow, arbitrary, code execution
advisories | CVE-2009-1856
SHA-256 | 48b4c5eb3ef997087bc4e824ebc4d6c72a992fb1b8e45a08db98b531d00f3505

iDEFENSE Security Advisory 2009-06-09.3

Change Mirror Download
iDefense Security Advisory 06.09.09
http://labs.idefense.com/intelligence/vulnerabilities/
Jun 09, 2009

I. BACKGROUND

Adobe Acrobat Reader/Acrobat are programs for viewing and editing
Portable Document Format (PDF) documents. For more information, see the
vendor's site found at the following link.

http://www.adobe.com/products/reader/
http://www.adobe.com/products/acrobatpro/

II. DESCRIPTION

Remote exploitation of an integer overflow vulnerability in multiple
versions of Adobe Systems Inc's Reader and Acrobat PDF reader and
processor could allow an attacker to execute arbitrary code with the
privileges of the current user.

The vulnerability occurs when parsing a FlateDecode filter inside a PDF
file. FlateDecode is a filter for data compressed with zlib deflate
compression method. Several parameters can be specified for the
FlateDecode filter. Those values are used in an arithmetic operation
that calculates the number of bytes to allocate for a heap buffer. This
calculation can overflow, which results in an undersized heap buffer
being allocated. This buffer is then overflowed with data decompressed
from the FlateDecode stream. This leads to a heap-based buffer overflow
that can result in arbitrary code execution.

III. ANALYSIS

Exploitation of this vulnerability allows the attacker to execute
arbitrary code with the privileges of the user opening the file. The
attacker will have to create a malicious PDF file and convince the
victim to open it. This can be accomplished by embedding the PDF file
into an IFRAME inside of a Web page, which will result in automatic
exploitation once the page is viewed. The file could also be e-mailed
as an attachment or placed on a file share. In these cases, a user
would have to manually open the file to trigger exploitation. If
preview is enable in Windows Explorer, this vulnerability can be
triggered simply by accessing a folder containing PDF files.

IV. DETECTION

Acrobat Reader and Acrobat Professional versions 7.1.0, 8.1.3, 9.0.0 and
prior versions are vulnerable.

V. WORKAROUND

None of the following workarounds will prevent exploitation, but they
can reduce potential attack vectors and make exploitation more
difficult.

Prevent PDF documents from being opened automatically by the Web browser
Disable JavaScript
Disable PDFShell extention by removing or renaming Acrord32info.exe file.
Follow best practice methodologies by avoiding opening files from
untrusted or unsolicited sources
Deploy DEP (Data Execution Prevention)

VI. VENDOR RESPONSE

Adobe has released a patch which addresses this issue. For more
information, consult their advisory (APSB09-07) at the following URL:

http://www.adobe.com/support/security/bulletins/apsb09-07.html

VII. CVE INFORMATION

The Common Vulnerabilities and Exposures (CVE) project has assigned the
name CVE-2009-1856 to this issue. This is a candidate for inclusion in
the CVE list (http://cve.mitre.org/), which standardizes names for
security problems.

VIII. DISCLOSURE TIMELINE

02/25/2009 - Initial Contact
02/25/2009 - Initial Response
02/25/2009 - PoC Requested
02/25/2009 - PoC Sent
06/05/2009 - Tentative disclosure date of 06/09/2009 set
06/09/2009 - Coordinated public disclosure

IX. CREDIT

This vulnerability was discovered by Jun Mao and Ryan Smith, iDefense
Labs

Get paid for vulnerability research
http://labs.idefense.com/methodology/vulnerability/vcp.php

Free tools, research and upcoming events
http://labs.idefense.com/

X. LEGAL NOTICES

Copyright © 2009 iDefense, Inc.

Permission is granted for the redistribution of this alert
electronically. It may not be edited in any way without the express
written consent of iDefense. If you wish to reprint the whole or any
part of this alert in any other medium other than electronically,
please e-mail customerservice@idefense.com for permission.

Disclaimer: The information in the advisory is believed to be accurate
at the time of publishing based on currently available information. Use
of the information constitutes acceptance for use in an AS IS condition.
There are no warranties with regard to this information. Neither the
author nor the publisher accepts any liability for any direct,
indirect, or consequential loss or damage arising from use of, or
reliance on, this information.
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close