Adobe Acrobat/Acrobat Reader ETD File Parser Format String Vulnerability
BID:11934
Info
Adobe Acrobat/Acrobat Reader ETD File Parser Format String Vulnerability
| Bugtraq ID: | 11934 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2004 12:00AM |
| Updated: | Dec 14 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Greg MacManus, iDEFENSE Labs. |
| Vulnerable: |
Adobe Reader 6.0.2 Adobe Reader 6.0.1 Adobe Reader 6.0 Adobe Acrobat 6.0.2 Adobe Acrobat 6.0.1 Adobe Acrobat 6.0 |
| Not Vulnerable: |
Adobe Reader 6.0.3 Adobe Acrobat 6.0.3 |
Discussion
Adobe Acrobat/Acrobat Reader ETD File Parser Format String Vulnerability
Adobe Acrobat/Acrobat Reader is reported prone to a remote format string vulnerability. The vulnerability is present in the ETD file parser when processing tag values. Reports indicate that the values supplied for certain tags are used as the format string in an unspecified formatted output function. Because an attacker can control the format string and the variables passed to the formatted output function, this vulnerability may be exploited to write to arbitrary locations within the memory of the process.
Adobe Acrobat/Acrobat Reader is reported prone to a remote format string vulnerability. The vulnerability is present in the ETD file parser when processing tag values. Reports indicate that the values supplied for certain tags are used as the format string in an unspecified formatted output function. Because an attacker can control the format string and the variables passed to the formatted output function, this vulnerability may be exploited to write to arbitrary locations within the memory of the process.
Exploit / POC
Adobe Acrobat/Acrobat Reader ETD File Parser Format String Vulnerability
The following examples are available:
<title>|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|</title>
<baseurl>|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|</baseurl>
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The following examples are available:
<title>|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|</title>
<baseurl>|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|%p|</baseurl>
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Adobe Acrobat/Acrobat Reader ETD File Parser Format String Vulnerability
Solution:
The vendor has released the following updates to address this vulnerability:
Adobe Acrobat 6.0
Adobe Reader 6.0
Adobe Acrobat 6.0.1
Adobe Reader 6.0.1
Adobe Reader 6.0.2
Adobe Acrobat 6.0.2
Solution:
The vendor has released the following updates to address this vulnerability:
Adobe Acrobat 6.0
-
Adobe Acrobat 6.0.3 update for Mac
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2676 -
Adobe Acrobat 6.0.3 update for Windows
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2677
Adobe Reader 6.0
-
Adobe Acrobat Reader 6.0.3 update for Mac
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2680 -
Adobe Acrobat Reader 6.0.3 update for Windows
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679
Adobe Acrobat 6.0.1
-
Adobe Acrobat 6.0.3 update for Mac
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2676 -
Adobe Acrobat 6.0.3 update for Windows
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2677
Adobe Reader 6.0.1
-
Adobe Acrobat Reader 6.0.3 update for Mac
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2680 -
Adobe Acrobat Reader 6.0.3 update for Windows
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679
Adobe Reader 6.0.2
-
Adobe Acrobat Reader 6.0.3 update for Mac
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2680 -
Adobe Acrobat Reader 6.0.3 update for Windows
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679
Adobe Acrobat 6.0.2
-
Adobe Acrobat 6.0.3 update for Mac
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2676 -
Adobe Acrobat 6.0.3 update for Windows
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2677
References
Adobe Acrobat/Acrobat Reader ETD File Parser Format String Vulnerability
References:
References: