Adobe Reader For Unix Local File Disclosure Vulnerability
BID:14165
Info
Adobe Reader For Unix Local File Disclosure Vulnerability
| Bugtraq ID: | 14165 |
| Class: | Design Error |
| CVE: |
CVE-2005-1841 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 06 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to Carsten Eiram. |
| Vulnerable: |
Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Desktop 4.0 Redhat Desktop 3.0 Adobe Acrobat Reader (UNIX) 5.0.10 Adobe Acrobat Reader (UNIX) 5.0.9 |
| Not Vulnerable: |
Adobe Acrobat Reader (UNIX) 7.0 Adobe Acrobat Reader (UNIX) 5.0.11 |
Discussion
Adobe Reader For Unix Local File Disclosure Vulnerability
Adobe Reader for Unix is affected by a local file disclosure vulnerability.
An attacker may gain access to temporary files created by the application and subsequently disclose a victim user's PDF files.
Adobe Reader 5.0.9 and 5.0.10 are vulnerable to this issue.
Adobe Reader for Unix is affected by a local file disclosure vulnerability.
An attacker may gain access to temporary files created by the application and subsequently disclose a victim user's PDF files.
Adobe Reader 5.0.9 and 5.0.10 are vulnerable to this issue.
Exploit / POC
Adobe Reader For Unix Local File Disclosure Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Adobe Reader For Unix Local File Disclosure Vulnerability
Solution:
The vendor has released Adobe Reader 7.0 as an upgrade for Adobe Reader 5.0.9 or 5.0.10 on Linux or Solaris. Adobe Reader 5.0.11 is available as an upgrade for 5.0.9 or 5.0.10 on IBM-AIX or HP-UX.
Red Hat has released advisory RHSA-2005:575-11 to address this issue. Please see the referenced advisory for more information.
Adobe Acrobat Reader (UNIX) 5.0.10
Adobe Acrobat Reader (UNIX) 5.0.9
Solution:
The vendor has released Adobe Reader 7.0 as an upgrade for Adobe Reader 5.0.9 or 5.0.10 on Linux or Solaris. Adobe Reader 5.0.11 is available as an upgrade for 5.0.9 or 5.0.10 on IBM-AIX or HP-UX.
Red Hat has released advisory RHSA-2005:575-11 to address this issue. Please see the referenced advisory for more information.
Adobe Acrobat Reader (UNIX) 5.0.10
-
Adobe Adobe Reader 5.0.11
For IBM-AIX or HP-UX.
www.adobe.com/products/acrobat/readstep2.html -
Adobe Adobe Reader 7.0
For Linux or Solaris.
www.adobe.com/products/acrobat/readstep2.html
Adobe Acrobat Reader (UNIX) 5.0.9
-
Adobe Adobe Reader 5.0.11
For IBM-AIX or HP-UX.
www.adobe.com/products/acrobat/readstep2.html -
Adobe Adobe Reader 7.0
For Linux or Solaris.
www.adobe.com/products/acrobat/readstep2.html
References
Adobe Reader For Unix Local File Disclosure Vulnerability
References:
References: