Executive brief
A stack-based buffer overflow vulnerability exists in the CoolType.dll component of Adobe Reader and Acrobat. The flaw is triggered by parsing a PDF document containing a specially crafted long field in a Smart INdependent Glyphlets (SING) table within a TrueType Font (TTF), allowing for remote code execution or denial of service.
Affected products
- Adobe Reader 9.x before 9.4, 8.x before 8.2.5, 9.3.4 and earlier
- Adobe Acrobat 9.x before 9.4, 8.x before 8.2.5, 9.3.4 and earlier
Timeline
- 2010-09: exploited: Exploited in the wild.
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.