CVE-2010-2883
Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.
- CVSS 3.1
- 7.3 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 82.48% probability · 100th percentile
- CISA KEV
- Listed 8 June 2022 · due 22 June 2022
- Weakness
- CWE-787
- Affected
- adobe/acrobat · adobe/acrobat reader
- Source
- psirt@adobe.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2010-2883
References
- http://blog.metasploit.com/2010/09/return-of-unpublished-adobe.htmlBroken Link
- http://community.websense.com/blogs/securitylabs/archive/2010/09/10/brief-analysis-on-adobe-reader-sing-table-parsing-vulnerability-cve-2010-2883.aspxBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00001.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.htmlBroken Link
- http://secunia.com/advisories/41340Broken Link, Vendor Advisory
- http://secunia.com/advisories/43025Broken Link, Vendor Advisory
- http://security.gentoo.org/glsa/glsa-201101-08.xmlThird Party Advisory
- http://www.adobe.com/support/security/advisories/apsa10-02.htmlVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb10-21.htmlVendor Advisory
- http://www.kb.cert.org/vuls/id/491991Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2010-0743.htmlBroken Link
- http://www.securityfocus.com/bid/43057Broken Link, Third Party Advisory, VDB Entry
- http://www.turbolinux.co.jp/security/2011/TLSA-2011-2j.txtBroken Link
- http://www.us-cert.gov/cas/techalerts/TA10-279A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2010/2331Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0191Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0344Broken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61635Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11586Broken Link
- http://blog.metasploit.com/2010/09/return-of-unpublished-adobe.htmlBroken Link
- http://community.websense.com/blogs/securitylabs/archive/2010/09/10/brief-analysis-on-adobe-reader-sing-table-parsing-vulnerability-cve-2010-2883.aspxBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00001.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.htmlBroken Link
- http://secunia.com/advisories/41340Broken Link, Vendor Advisory
- http://secunia.com/advisories/43025Broken Link, Vendor Advisory
- http://security.gentoo.org/glsa/glsa-201101-08.xmlThird Party Advisory
- http://www.adobe.com/support/security/advisories/apsa10-02.htmlVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb10-21.htmlVendor Advisory
- http://www.kb.cert.org/vuls/id/491991Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2010-0743.htmlBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.