Adobe Reader For Unix Remote Buffer Overflow Vulnerability
BID:14153
Info
Adobe Reader For Unix Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 14153 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-1625 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | iDEFENSE Labs discovered this issue. |
| Vulnerable: |
S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.1 x86_64 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Desktop 4.0 Redhat Desktop 3.0 Gentoo Linux Adobe Acrobat Reader (UNIX) 5.0.10 Adobe Acrobat Reader (UNIX) 5.0.9 |
| Not Vulnerable: |
Adobe Acrobat Reader (UNIX) 7.0 Adobe Acrobat Reader (UNIX) 5.0.11 |
Discussion
Adobe Reader For Unix Remote Buffer Overflow Vulnerability
Adobe Reader for Unix is affected by a remote buffer overflow vulnerability.
An attacker can exploit this issue by crafting a malicious PDF file and sending it to a vulnerable user. If the victim user opens this PDF file, the attacker may be able to execute arbitrary code on the affected computer and gain unauthorized access in the context of the user.
Adobe Reader 5.0.9 and 5.0.10 are vulnerable to this issue.
Adobe Reader for Unix is affected by a remote buffer overflow vulnerability.
An attacker can exploit this issue by crafting a malicious PDF file and sending it to a vulnerable user. If the victim user opens this PDF file, the attacker may be able to execute arbitrary code on the affected computer and gain unauthorized access in the context of the user.
Adobe Reader 5.0.9 and 5.0.10 are vulnerable to this issue.
Exploit / POC
Adobe Reader For Unix Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Adobe Reader For Unix Remote Buffer Overflow Vulnerability
Solution:
The vendor has released Adobe Reader 7.0 as an upgrade for Adobe Reader 5.0.9 or 5.0.10 on Linux or Solaris. Adobe Reader 5.0.11 is available as an upgrade for 5.0.9 or 5.0.10 on IBM-AIX or HP-UX.
Red Hat has released advisory RHSA-2005:575-11 to address this issue. Please see the referenced advisory for more information.
Gentoo Linux has relased advisory GLSA 200507-09 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=app-text/acroread-7.0"
Please see the referenced advisory for further information.
SUSE has released advisory SUSE-SA:2005:042 to address this issue. Please see the referenced advisory for more information.
Adobe Acrobat Reader (UNIX) 5.0.10
Adobe Acrobat Reader (UNIX) 5.0.9
Solution:
The vendor has released Adobe Reader 7.0 as an upgrade for Adobe Reader 5.0.9 or 5.0.10 on Linux or Solaris. Adobe Reader 5.0.11 is available as an upgrade for 5.0.9 or 5.0.10 on IBM-AIX or HP-UX.
Red Hat has released advisory RHSA-2005:575-11 to address this issue. Please see the referenced advisory for more information.
Gentoo Linux has relased advisory GLSA 200507-09 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=app-text/acroread-7.0"
Please see the referenced advisory for further information.
SUSE has released advisory SUSE-SA:2005:042 to address this issue. Please see the referenced advisory for more information.
Adobe Acrobat Reader (UNIX) 5.0.10
-
Adobe Adobe Reader 5.0.11
For IBM-AIX or HP-UX.
www.adobe.com/products/acrobat/readstep2.html -
Adobe Adobe Reader 7.0
For Linux or Solaris.
www.adobe.com/products/acrobat/readstep2.html
Adobe Acrobat Reader (UNIX) 5.0.9
-
Adobe Adobe Reader 5.0.11
For IBM-AIX or HP-UX.
www.adobe.com/products/acrobat/readstep2.html -
Adobe Adobe Reader 7.0
For Linux or Solaris.
www.adobe.com/products/acrobat/readstep2.html
References
Adobe Reader For Unix Remote Buffer Overflow Vulnerability
References:
References: