New issue
Advanced search Search tips
Starred by 5 users
Status: Fixed
Owner:
Closed: May 2015
Cc:



Sign in to add a comment
Adobe Reader X and XI for Windows out-of-bounds read in CoolType.dll
Project Member Reported by mjurczyk@google.com, Oct 30 2014 Back to list
The following access violation was observed in Adobe Reader X and XI for Windows:

(d4c.4c4): Access violation - code c0000005 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
eax=0699b912 ebx=00000000 ecx=0699b912 edx=000000ff esi=10d9b913 edi=0699b902
eip=693136d1 esp=1133d918 ebp=1133d988 iopl=0         nv up ei ng nz na pe cy
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00010287
CoolType+0x536d1:
693136d1 660fb64708      movzx   ax,byte ptr [edi+8]        ds:0023:0699b90a=??
0:014> !address edi+8

Usage:                  PageHeap
Base Address:           0699b000
End Address:            0699c000
Region Size:            00001000
State:                  00002000	MEM_RESERVE
Protect:                <info not present at the target>
Type:                   00020000	MEM_PRIVATE
Allocation Base:        06950000
Allocation Protect:     00000001	PAGE_NOACCESS
More info:              !heap -p 0x5251000
More info:              !heap -p -a 0x699b90a
0:014> k
ChildEBP RetAddr  
WARNING: Stack unwind information not available. Following frames may be wrong.
1133d988 00000000 CoolType+0x536d1

Notes:

- Reproduces on Adobe Reader X (10.1.12) and Adobe Reader XI (11.0.09) for Windows, on Windows 7, with Application Verifier enabled.

- The “EDI” register points into a reserved PageHeap memory page following a regular heap allocation. This implies this is an out-of-bounds memory access relative to a heap-based buffer.

- Sometimes several attempts are required to reproduce the case.

- Attached samples: signal_sigsegv_f74f5598_9029_707.pdf (crashing file), 707.pdf (original file).

This bug is subject to a 90 day disclosure deadline. If 90 days elapse without a broadly available patch, then the bug report will automatically become visible to the public.


 
signal_sigsegv_f74f5598_9029_707.zip
1.6 MB Download
Project Member Comment 1 by mjurczyk@google.com, Oct 30 2014
The original 707.pdf sample is available from Drive: https://drive.google.com/a/google.com/file/d/0B0tJqpS3FKtCSlUxWFNsaEQydVE/view?usp=sharing.
Project Member Comment 2 by mjurczyk@google.com, Oct 30 2014
Owner: mjurczyk@google.com
Project Member Comment 3 by mjurczyk@google.com, Oct 31 2014
Labels: Id-3108
Project Member Comment 4 by mjurczyk@google.com, Dec 10 2014
Labels: CVE-2014-9161
Project Member Comment 5 by mjurczyk@google.com, Jan 27 2015
The vendor communication timeline is as follows:

10/30/14 Vulnerability is reported to Adobe PSIRT.
10/31/14 Adobe PSIRT confirms reception of the reports and assigns internal case ID (PSIRT-3108).
12/05/14 Adobe PSIRT informs us that the vulnerability would be fixed in next Tuesday's Acrobat and Reader security bulletins, and assigns CVE-2014-9161 for the issue.
12/08/14 Adobe PSIRT sends and update claiming that the issue is fixed for Windows, but the vendor has been unable to introduce a fix in the update for Mac, so the case is kept open until an update is released for Mac.
01/27/15 We send a heads-up to Adobe that the 90 day deadline elapses on the next day and we will remove the view restriction.

We have reproduced the crash on a fully updated Adobe Reader for Mac. We are currently not aware of any mitigations for the vulnerability.
Project Member Comment 6 by mjurczyk@google.com, Jan 29 2015
Labels: -Restrict-View-Commit
Deadline exceeded - automatically derestricting
Comment 7 by cevans@google.com, Feb 9 2015
Labels: Deadline-Exceeded
Comment 8 by cevans@google.com, May 12 2015
Labels: Fixed-2015-May-12
Status: Fixed
https://helpx.adobe.com/security/products/reader/apsb15-10.html
Thank you

http://www.wdfshare.com
That script is what ya kak? Please explain to me, because I wanted depth. and want to learn

http://www.sewuanblog.tk/2016/01/cara-membuat-plugin-comment-facebook-di.html
Sign in to add a comment