Immunity, Inc.
Name acrobat_jbig
CVE CVE-2009-0658
Exploit Pack CANVAS
DescriptionAdobe Acrobat Reader 9.0 JBIG Parser (Stack Overwrite)
NotesCVE Name: CVE-2009-0658
VENDOR: Adobe
Notes:
Not to be used from IE (via the HTTP Server) as memory moves around too much.

Instead, generate a PDF file and email it to your target.

This exploit requires at least 300mb of RAM on your target's machine for the
heap spray. It does not require JavaScript to be enabled in Acrobat Reader.
This was tested on Acrobat Reader 9.0 on XP SP2/3.

VersionsAffected: Adobe Acrobat Reader 9.0/8.1.3 and lower
Repeatability:
CVE URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0658
References: http://secunia.com/advisories/33901/
CERT Advisory: http://www.kb.cert.org/vuls/id/905281
Date public: 02/20/2009
CVSS: 9.3

Learn more about the CANVAS Exploit Pack here: CANVAS