Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Adobe Reader PDF CIDFont Dictionary Memory Corruption (APSB11-16; CVE-2011-2105)

Subscribe

Check Point Reference: CPAI-2011-311
Date Published:
Severity:
Last Updated:
Source: Adobe Security Bulletin APSB11-16
Industry Reference(s): CVE-2011-2105
Protection Provided by: Security Gateway
  • R75
  • R71
  • R70
IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
Adobe Reader X (10.0.1) and earlier 10.x versions for Windows
Adobe Reader X (10.0.3) and earlier 10.x versions for Macintosh
Adobe Reader 9.4.4 and earlier 9.x versions for Windows and Macintosh
Adobe Reader 8.2.6 and earlier 8.x versions for Windows and Macintosh
Adobe Acrobat X (10.0.3) and earlier 10.x versions for Windows and Macintosh
Adobe Acrobat 9.4.4 and earlier 9.x versions for Windows and Macintosh
Adobe Acrobat 8.2.6 and earlier 8.x versions for Windows and Macintosh
Vulnerability Description
A memory corruption vulnerability has been reported in Adobe Reader. Successful exploitation of this vulnerability may cause a memory corruption, causing the application to crash, and may allow execution of arbitrary code once a malicious PDF file is loaded on a vulnerable system.
Update/Patch Available
Upgrade to newer version of Adobe Reader
Vulnerability Details
This is a memory corruption vulnerability. The vulnerability is due to an error in Adobe Reader when handling PDF files that contain CIDFont Dictionary entries. A remote attacker could trigger these flaws via a specially crafted PDF file. Successful exploitation of this vulnerability may cause a memory corruption, causing the application to crash, and may allow execution of arbitrary code once a malicious PDF file is loaded on a vulnerable system.

Protection Overview
This protection will detect and block the transferring of malformed PDF files over HTTP.

To configure the defense, select your product from the list below and follow the related protection steps.

Security Gateway R75 / R71 / R70

How Can I Protect My Network?
1. In the IPS tab, click Protections and find the Adobe Reader PDF CIDFont Dictionary Memory Corruption (APSB11-16) protection using the Search tool and Edit the protection's settings.
2. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:
Attack Name: Adobe Reader Violation
Attack Information: Adobe Reader PDF CIDFont dictionary memory corruption (APSB11-16)

IPS-1 & IPS1-NGX R65

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Application Intelligence > Badfiles, and select the PDF Skimmer protection group.
3. Click Adobe Reader PDF CIDFont Dictionary Memory Corruption (APSB11-16).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

Alert Name: Badfiles PDF Skimming
Description: Adobe Reader PDF CIDFont Dictionary Memory Corruption (APSB11-16)