Adobe Acrobat, Reader/Flash CVE-2010-3654远程代码执行漏洞

漏洞起因
边界条件错误
危险等级

 
影响系统
Google Chrome 5.0.375 99
Google Chrome 5.0.375 99
Google Chrome 5.0.375 86
Google Chrome 5.0.375 86
Google Chrome 5.0.375 127
Google Chrome 5.0.375 125
Google Chrome 5.0.375 125
Google Chrome 5.0.375 .70
Google Chrome 5.0.375 .55
Google Chrome 7.0.517.41
Google Chrome 6.0.472.42
Google Chrome 6.0.472.41
Google Chrome 6.0.472.40
Google Chrome 6.0.472.4
Google Chrome 6.0.472.39
Google Chrome 6.0.472.38
Google Chrome 6.0.472.37
Google Chrome 6.0.472.36
Google Chrome 6.0.472.35
Google Chrome 6.0.472.34
Google Chrome 6.0.472.33
Google Chrome 6.0.472.32
Google Chrome 6.0.472.31
Google Chrome 6.0.472.30
Google Chrome 6.0.472.3
Google Chrome 6.0.472.29
Google Chrome 6.0.472.28
Google Chrome 6.0.472.27
Google Chrome 6.0.472.26
Google Chrome 6.0.472.25
Google Chrome 6.0.472.24
Google Chrome 6.0.472.23
Google Chrome 6.0.472.22
Google Chrome 6.0.472.21
Google Chrome 6.0.472.20
Google Chrome 6.0.472.2
Google Chrome 6.0.472.19
Google Chrome 6.0.472.18
Google Chrome 6.0.472.17
Google Chrome 6.0.472.16
Google Chrome 6.0.472.15
Google Chrome 6.0.472.14
Google Chrome 6.0.472.13
Google Chrome 6.0.472.12
Google Chrome 6.0.472.11
Google Chrome 6.0.472.10
Google Chrome 6.0.472.1
Google Chrome 6.0.472.0
Google Chrome 6.0.471.0
Google Chrome 6.0.470.0
Google Chrome 6.0.469.0
Google Chrome 6.0.467.0
Google Chrome 6.0.466.6
Google Chrome 6.0.466.5
Google Chrome 6.0.466.4
Google Chrome 6.0.466.3
Google Chrome 6.0.466.2
Google Chrome 6.0.466.1
Google Chrome 6.0.466.0
Google Chrome 6.0.465.2
Google Chrome 6.0.465.1
Google Chrome 6.0.464.1
Google Chrome 6.0.462.0
Google Chrome 6.0.461.0
Google Chrome 6.0.460.0
Google Chrome 6.0.459.0
Google Chrome 6.0.458.2
Google Chrome 6.0.458.1
Google Chrome 6.0.458.0
Google Chrome 6.0.457.0
Google Chrome 6.0.456.0
Google Chrome 6.0.455.0
Google Chrome 6.0.454.0
Google Chrome 6.0.453.1
Google Chrome 6.0.453.0
Google Chrome 6.0.452.1
Google Chrome 6.0.452.0
Google Chrome 6.0.451.0
Google Chrome 6.0.450.4
Google Chrome 6.0.450.3
Google Chrome 6.0.450.2
Google Chrome 6.0.450.1
Google Chrome 6.0.450.0
Google Chrome 6.0.449.0
Google Chrome 6.0.447.2
Google Chrome 6.0.447.1
Google Chrome 6.0.447.0
Google Chrome 6.0.446.0
Google Chrome 6.0.445.1
Google Chrome 6.0.445.0
Google Chrome 6.0.444.0
Google Chrome 6.0.443.0
Google Chrome 6.0.441.0
Google Chrome 6.0.440.0
Google Chrome 6.0.438.0
Google Chrome 6.0.437.3
Google Chrome 6.0.437.2
Google Chrome 6.0.437.1
Google Chrome 6.0.437.0
Google Chrome 6.0.436.0
Google Chrome 6.0.435.0
Google Chrome 6.0.434.0
Google Chrome 6.0.433.0
Google Chrome 6.0.432.0
Google Chrome 6.0.431.0
Google Chrome 6.0.430.0
Google Chrome 6.0.428.0
Google Chrome 6.0.427.0
Google Chrome 6.0.426.0
Google Chrome 6.0.425.0
Google Chrome 6.0.424.0
Google Chrome 6.0.423.0
Google Chrome 6.0.422.0
Google Chrome 6.0.421.0
Google Chrome 6.0.419.0
Google Chrome 6.0.418.9
Google Chrome 6.0.418.8
Google Chrome 6.0.418.7
Google Chrome 6.0.418.6
Google Chrome 6.0.418.5
Google Chrome 6.0.418.4
Google Chrome 6.0.418.3
Google Chrome 6.0.418.2
Google Chrome 6.0.418.1
Google Chrome 6.0.418.0
Google Chrome 6.0.417.0
Google Chrome 6.0.416.1
Google Chrome 6.0.416.0
Google Chrome 6.0.415.1
Google Chrome 6.0.415.0
Google Chrome 6.0.414.0
Google Chrome 6.0.413.0
Google Chrome 6.0.412.0
Google Chrome 6.0.411.0
Google Chrome 6.0.410.0
Google Chrome 6.0.409.0
Google Chrome 6.0.408.9
Google Chrome 6.0.408.8
Google Chrome 6.0.408.7
Google Chrome 6.0.408.6
Google Chrome 6.0.408.5
Google Chrome 6.0.408.4
Google Chrome 6.0.408.3
Google Chrome 6.0.408.2
Google Chrome 6.0.408.10
Google Chrome 6.0.408.1
Google Chrome 6.0.408.0
Google Chrome 6.0.407.0
Google Chrome 6.0.406.0
Google Chrome 6.0.405.0
Google Chrome 6.0.404.2
Google Chrome 6.0.404.1
Google Chrome 6.0.404.0
Google Chrome 6.0.403.0
Google Chrome 6.0.401.1
Google Chrome 6.0.401.0
Google Chrome 6.0.400.0
Google Chrome 6.0.399.0
Google Chrome 5.0.375.98
Google Chrome 5.0.375.97
Google Chrome 5.0.375.96
Google Chrome 5.0.375.95
Google Chrome 5.0.375.94
Google Chrome 5.0.375.93
Google Chrome 5.0.375.92
Google Chrome 5.0.375.91
Google Chrome 5.0.375.90
Google Chrome 5.0.375.89
Google Chrome 5.0.375.88
Google Chrome 5.0.375.87
Google Chrome 5.0.375.85
Google Chrome 5.0.375.84
Google Chrome 5.0.375.83
Google Chrome 5.0.375.82
Google Chrome 5.0.375.81
Google Chrome 5.0.375.80
Google Chrome 5.0.375.79
Google Chrome 5.0.375.78
Google Chrome 5.0.375.77
Google Chrome 5.0.375.76
Google Chrome 5.0.375.75
Google Chrome 5.0.375.74
Google Chrome 5.0.375.73
Google Chrome 5.0.375.72
Google Chrome 5.0.375.71
Google Chrome 5.0.375.69
Google Chrome 5.0.375.68
Google Chrome 5.0.375.67
Google Chrome 5.0.375.66
Google Chrome 5.0.375.65
Google Chrome 5.0.375.64
Google Chrome 5.0.375.63
Google Chrome 5.0.375.62
Google Chrome 5.0.375.61
Google Chrome 5.0.375.60
Google Chrome 5.0.375.59
Google Chrome 5.0.375.58
Google Chrome 5.0.375.57
Google Chrome 5.0.375.56
Google Chrome 5.0.375.54
Google Chrome 5.0.375.53
Google Chrome 5.0.375.52
Google Chrome 5.0.375.51
Google Chrome 5.0.375.50
Google Chrome 5.0.375.49
Google Chrome 5.0.375.48
Google Chrome 5.0.375.47
Google Chrome 5.0.375.46
Google Chrome 5.0.375.45
Google Chrome 5.0.375.44
Google Chrome 5.0.375.43
Google Chrome 5.0.375.42
Google Chrome 5.0.375.41
Google Chrome 5.0.375.40
Google Chrome 5.0.375.39
Google Chrome 5.0.375.126
Adobe Reader 9.3.4
Adobe Reader 9.3.4
Adobe Reader 9.3.3
Adobe Reader 9.3.2
Adobe Reader 9.3.1
Adobe Reader 9.1.3
Adobe Reader 9.1.2
Adobe Reader 9.1.1
Adobe Reader 9.4
Adobe Reader 9.3
Adobe Reader 9.2
Adobe Reader 9.1
Adobe Reader 9
Adobe Flash Player 10.1.53 .64
Adobe Flash Player 10.1.51 .66
Adobe Flash Player 10.0.45 2
Adobe Flash Player 10.0.45 2
Adobe Flash Player 10.0.45 2
Adobe Flash Player 10.0.32 18
Adobe Flash Player 10.0.22 .87
Adobe Flash Player 10.0.15 .3
Adobe Flash Player 10.0.12 .36
Adobe Flash Player 10.0.12 .35
Adobe Flash Player 10.1.95.2
Adobe Flash Player 10.1.95.1
Adobe Flash Player 10.1.92.10
Adobe Flash Player 10.1.92.10
Adobe Flash Player 10.1.85.3
Adobe Flash Player 10.1.82.76
Adobe Flash Player 10.1 Release Candida
Adobe Flash Player 10.0.42.34
Adobe Flash Player 10.0.32.18
Adobe Flash Player 10
Adobe Acrobat Standard 9.3.4
Adobe Acrobat Standard 9.3.4
Adobe Acrobat Standard 9.3.3
Adobe Acrobat Standard 9.3.2
Adobe Acrobat Standard 9.3.1
Adobe Acrobat Standard 9.1.3
Adobe Acrobat Standard 9.1.2
Adobe Acrobat Standard 9.4
Adobe Acrobat Standard 9.3
Adobe Acrobat Standard 9.2
Adobe Acrobat Standard 9.1
Adobe Acrobat Standard 9
Adobe Acrobat Professional 9.3.4
Adobe Acrobat Professional 9.3.3
Adobe Acrobat Professional 9.3.2
Adobe Acrobat Professional 9.3.1
Adobe Acrobat Professional 9.1.3
Adobe Acrobat Professional 9.1.2
Adobe Acrobat Professional 9.4
Adobe Acrobat Professional 9.3
Adobe Acrobat Professional 9.2
Adobe Acrobat Professional 9.1
Adobe Acrobat Professional 9 Extended
Adobe Acrobat Professional 9
Adobe Acrobat 9.3.3
Adobe Acrobat 9.3.3
Adobe Acrobat 9.3.2
Adobe Acrobat 9.3.1
Adobe Acrobat 9.1.1
Adobe Acrobat 8.2.4
Adobe Acrobat 9.4
Adobe Acrobat 9.3
Adobe Acrobat 9.2
 
不受影响系统
 
危害
远程攻击者可以利用漏洞以应用程序安全上下文执行任意代码。
 
攻击所需条件
攻击者必须构建恶意PDF文件,诱使用户访问触发此漏洞。
 
漏洞信息
Adobe Reader/Acrobat是流行的处理PDF文件的应用程序。Adobe Flash Player是一款Flash文件处理程序。
Windows, Macintosh, Linux和Solaris平台下的Adobe Flash Player 10.1.85.3和之前版本,Android平台下的Adobe Flash Player 10.1.95.2和之前版本,Windows, Macintosh和UNIX操作系统下的Adobe Reader 9.4和早期9.x版本,Windows和Macintosh操作系统下的Adobe Acrobat 9.4和早期9.x版本包含的authplay.dll组件存在严重的安全漏洞。
此漏洞(CVE-2010-3654)可导致受影响系统崩溃或允许攻击者完全控制受影响系统。根据报告,目前用于挂马的版本利用Adobe Reader/Acrobat 9.x进行攻击。目前还没有注意到针对Adobe Flash Player的攻击。
注:Adobe Reader/Acrobat 8.x证实不受此漏洞影响,Adobe Reader for Android也不受此漏洞影响。
 
测试方法
 
厂商解决方案
Adobe计划在2010,11月9日发布Flash升级程序,在2010,11月15号的那星期发布Adobe Acrobat/Reader的升级程序:
http://www.adobe.com/
 
漏洞提供者
Adobe

发表评论?

0 条评论。

发表评论