CVE-2010-1241 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1241): The custom heap management system in Adobe Reader 9.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted PDF document, aka FG-VD-10-005.
Adobe expects to make these quarterly updates available on April 13, 2010.
The new version is available, please bump ASAP!
Printing, when do you plan to add an ebuild for this?
I'm going to add it later today.
acroread-9.3.2 in CVS now, thanks.
rerating
CVE-2010-0190 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0190): Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CVE-2010-0191 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0191): Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified vectors, related to a "prefix protocol handler vulnerability." CVE-2010-0192 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0192): Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0193 and CVE-2010-0196. CVE-2010-0193 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0193): Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0192 and CVE-2010-0196. CVE-2010-0194 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0194): Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0197, CVE-2010-0201, and CVE-2010-0204. CVE-2010-0195 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0195): Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, do not properly handle fonts, which allows attackers to execute arbitrary code via unspecified vectors. CVE-2010-0196 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0196): Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0192 and CVE-2010-0193. CVE-2010-0197 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0197): Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0201, and CVE-2010-0204. CVE-2010-0198 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0198): Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0199, CVE-2010-0202, and CVE-2010-0203. CVE-2010-0199 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0199): Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0202, and CVE-2010-0203. CVE-2010-0201 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0201): Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0204. CVE-2010-0202 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0202): Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0199, and CVE-2010-0203. CVE-2010-0203 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0203): Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0199, and CVE-2010-0202. CVE-2010-0204 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0204): Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0201.
Arches, please test and mark stable: =app-text/acroread-9.3.2 Target keywords : "amd64 x86"
x86 stable
amd64 stable, all arches done.
Thanks everyone, GLSA request filed.
This was GLSA 201009-05.