Adobe Acrobat Reader ActiveX Control LoadFile Information Disclosure Vulnerability
BID:12989
Info
Adobe Acrobat Reader ActiveX Control LoadFile Information Disclosure Vulnerability
| Bugtraq ID: | 12989 |
| Class: | Design Error |
| CVE: |
CVE-2005-0035 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2005 12:00AM |
| Updated: | Jul 12 2009 11:56AM |
| Credit: | This vulnerability was independently discovered by both NISCC and Robert Fly <[email protected]>. |
| Vulnerable: |
Adobe Reader 7.0 Adobe Reader 6.0.3 Adobe Reader 6.0.2 Adobe Reader 6.0.1 Adobe Reader 6.0 Adobe Reader 5.1 Adobe Reader 5.0.5 Adobe Reader 5.0 Adobe Reader 4.0.5 A Adobe Reader 4.0 5c Adobe Reader 4.0 5 Adobe Reader 4.0 Adobe Reader 3.0 |
| Not Vulnerable: |
Adobe Reader 7.0.1 |
Discussion
Adobe Acrobat Reader ActiveX Control LoadFile Information Disclosure Vulnerability
It is reported that the Adobe Acrobat Reader ActiveX control is prone to information disclosure vulnerability. Reports indicate that the Adobe Acrobat Reader ActiveX control, may be employed to disclose the existence of a target file.
Information that is harvested by leveraging this vulnerability may be used to aid in further attacks.
This vulnerability is reported to affect Adobe Acrobat Reader version 7.0 and prior versions.
It is reported that the Adobe Acrobat Reader ActiveX control is prone to information disclosure vulnerability. Reports indicate that the Adobe Acrobat Reader ActiveX control, may be employed to disclose the existence of a target file.
Information that is harvested by leveraging this vulnerability may be used to aid in further attacks.
This vulnerability is reported to affect Adobe Acrobat Reader version 7.0 and prior versions.
Exploit / POC
Adobe Acrobat Reader ActiveX Control LoadFile Information Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Adobe Acrobat Reader ActiveX Control LoadFile Information Disclosure Vulnerability
Solution:
It is reported that this vulnerability is addressed in Adobe Acrobat Reader version 7.0.1:
Adobe Reader 3.0
Adobe Reader 4.0
Adobe Reader 4.0 5
Adobe Reader 4.0 5c
Adobe Reader 4.0.5 A
Adobe Reader 5.0
Adobe Reader 5.0.5
Adobe Reader 5.1
Adobe Reader 6.0
Adobe Reader 6.0.1
Adobe Reader 6.0.2
Adobe Reader 6.0.3
Adobe Reader 7.0
Solution:
It is reported that this vulnerability is addressed in Adobe Acrobat Reader version 7.0.1:
Adobe Reader 3.0
-
Adobe Adobe Acrobat Reader 7.0.1
http://www.adobe.com/support/downloads/main.html
Adobe Reader 4.0
-
Adobe Adobe Acrobat Reader 7.0.1
http://www.adobe.com/support/downloads/main.html
Adobe Reader 4.0 5
-
Adobe Adobe Acrobat Reader 7.0.1
http://www.adobe.com/support/downloads/main.html
Adobe Reader 4.0 5c
-
Adobe Adobe Acrobat Reader 7.0.1
http://www.adobe.com/support/downloads/main.html
Adobe Reader 4.0.5 A
-
Adobe Adobe Acrobat Reader 7.0.1
http://www.adobe.com/support/downloads/main.html
Adobe Reader 5.0
-
Adobe Adobe Acrobat Reader 7.0.1
http://www.adobe.com/support/downloads/main.html
Adobe Reader 5.0.5
-
Adobe Adobe Acrobat Reader 7.0.1
http://www.adobe.com/support/downloads/main.html
Adobe Reader 5.1
-
Adobe Adobe Acrobat Reader 7.0.1
http://www.adobe.com/support/downloads/main.html
Adobe Reader 6.0
-
Adobe Adobe Acrobat Reader 7.0.1
http://www.adobe.com/support/downloads/main.html
Adobe Reader 6.0.1
-
Adobe Adobe Acrobat Reader 7.0.1
http://www.adobe.com/support/downloads/main.html
Adobe Reader 6.0.2
-
Adobe Adobe Acrobat Reader 7.0.1
http://www.adobe.com/support/downloads/main.html
Adobe Reader 6.0.3
-
Adobe Adobe Acrobat Reader 7.0.1
http://www.adobe.com/support/downloads/main.html
Adobe Reader 7.0
-
Adobe Adobe Acrobat Reader 7.0.1
http://www.adobe.com/support/downloads/main.html
References
Adobe Acrobat Reader ActiveX Control LoadFile Information Disclosure Vulnerability
References:
References:
- Adobe Reader Download Page (Adobe)
- NISCC Vulnerability Advisory 482323/NISCC/ADOBE (NISCC)
- Local file detection found through Adobe Reader ActiveX control ("Hyperdose Security"
)