Adobe Acrobat Reader Email Message Remote Buffer Overflow Vulnerability
BID:11923
Info
Adobe Acrobat Reader Email Message Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11923 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1152 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2004 12:00AM |
| Updated: | Jul 12 2009 09:26AM |
| Credit: | Greg MacManus of iDEFENSE Labs is credited with the discovery of this issue. |
| Vulnerable: |
Adobe Acrobat Reader (UNIX) 5.0.9 |
| Not Vulnerable: |
Adobe Acrobat Reader (UNIX) 5.0.10 |
Discussion
Adobe Acrobat Reader Email Message Remote Buffer Overflow Vulnerability
A remote buffer overflow vulnerability reportedly affects the email message checking functionality in Adobe Acrobat Reader for Unix. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
It should be noted that this issue only affects Adobe Acrobat Reader for the Unix platform.
A remote buffer overflow vulnerability reportedly affects the email message checking functionality in Adobe Acrobat Reader for Unix. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
It should be noted that this issue only affects Adobe Acrobat Reader for the Unix platform.
Exploit / POC
Adobe Acrobat Reader Email Message Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Adobe Acrobat Reader Email Message Remote Buffer Overflow Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue. Please see the referenced vendor knowledgebase article.
Gentoo Linux has released an advisory (GLSA 200412-12) resolving this issue. All Adobe Acrobat Reader users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-text/acroread-5.10"
For more information, please see the referenced Gentoo Linux advisory.
Red Hat has released advisory RHSA-2004:674-07 to address this issue in Red Hat Enterprise Linux. Please see the advisory in Web references for more information.
SuSE Linux has released a summary report (SUSE-SR:2005:001) advising that this as well as other issues have been resolved. Please see the referenced advisory for more information.
Adobe Acrobat Reader (UNIX) 5.0.9
Solution:
The vendor has released an upgrade dealing with this issue. Please see the referenced vendor knowledgebase article.
Gentoo Linux has released an advisory (GLSA 200412-12) resolving this issue. All Adobe Acrobat Reader users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-text/acroread-5.10"
For more information, please see the referenced Gentoo Linux advisory.
Red Hat has released advisory RHSA-2004:674-07 to address this issue in Red Hat Enterprise Linux. Please see the advisory in Web references for more information.
SuSE Linux has released a summary report (SUSE-SR:2005:001) advising that this as well as other issues have been resolved. Please see the referenced advisory for more information.
Adobe Acrobat Reader (UNIX) 5.0.9
-
Adobe Acrobat Reader for Unix 5.0.10
http://www.adobe.com/support/downloads/product.jsp?product=10&platform =unix -
SuSE acroread-5.010-4.1.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/acroread-5.010-4. 1.i586.rpm -
SuSE acroread-5.010-4.2.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/acroread-5.010-4. 2.i586.rpm -
SuSE acroread-5.010-5.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/acroread-5.010-5. i586.rpm -
SuSE acroread-5.010-5.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/acroread-5.010-5. i586.rpm -
SuSE acroread-5.010-5.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/acroread-5.010-5. i586.rpm
References
Adobe Acrobat Reader Email Message Remote Buffer Overflow Vulnerability
References:
References:
- Adobe Reader Download Page (Adobe)
- mailListIsPdf() Buffer Overflow Vulnerability (Adobe)
- RHSA-2004:674-07 - Updated acrobat package fixes security issue (RedHat)
- iDEFENSE Security Advisory 12.14.04 - Adobe Acrobat Reader 5.0.9 mailListIsPdf() ("customer service mailbox"
)