Adobe Acrobat / Adobe Reader Local Privilege Escalation Vulnerability
BID:18945
CVE-2006-3452 |Info
Adobe Acrobat / Adobe Reader Local Privilege Escalation Vulnerability
| Bugtraq ID: | 18945 |
| Class: | Design Error |
| CVE: |
CVE-2006-3452 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 11 2006 12:00AM |
| Updated: | Jul 14 2006 04:23PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Adobe Reader 6.0.4 Adobe Reader 6.0.3 Adobe Reader 6.0.2 Adobe Reader 6.0.1 Adobe Reader 6.0 Adobe Reader 5.1 Adobe Reader 5.0.10 Adobe Reader 5.0.5 Adobe Reader 5.0 Adobe Reader 4.0.5 A Adobe Reader 4.0 5c Adobe Reader 4.0 5 Adobe Reader 4.0 Adobe Reader 3.0 Adobe Acrobat 6.0.4 Adobe Acrobat 6.0.3 Adobe Acrobat 6.0.2 Adobe Acrobat 6.0.1 Adobe Acrobat 6.0 Adobe Acrobat 5.0.10 Adobe Acrobat 5.0.5 Adobe Acrobat 5.0 Adobe Acrobat 4.0.5 A Adobe Acrobat 4.0 5c Adobe Acrobat 4.0 5 Adobe Acrobat 4.0 Adobe Acrobat 3.1 Adobe Acrobat 3.0 |
| Not Vulnerable: | |
Discussion
Adobe Acrobat / Adobe Reader Local Privilege Escalation Vulnerability
Adobe Acrobat / Adobe Reader for Mac are prone to a privilege-escalation vulnerability.
The vulnerability presents itself because of insecure default permissions associated with installed files and folders.
Adobe Acrobat and Adobe Reader versions 6.0.4 and prior are affected. Note that this issue arises only on multiuser systems on Mac OS X platforms.
Adobe Acrobat / Adobe Reader for Mac are prone to a privilege-escalation vulnerability.
The vulnerability presents itself because of insecure default permissions associated with installed files and folders.
Adobe Acrobat and Adobe Reader versions 6.0.4 and prior are affected. Note that this issue arises only on multiuser systems on Mac OS X platforms.
Exploit / POC
Adobe Acrobat / Adobe Reader Local Privilege Escalation Vulnerability
An exploit is not required to launch an attack.
An exploit is not required to launch an attack.
Solution / Fix
Adobe Acrobat / Adobe Reader Local Privilege Escalation Vulnerability
Solution:
Adobe has released updates to address this issue. The vendor advises customers to obtain version 6.0.5 using the automatic update facility or from the following location:
http://www.adobe.com/support/downloadshttp://www.adobe.com/support/downloads
Solution:
Adobe has released updates to address this issue. The vendor advises customers to obtain version 6.0.5 using the automatic update facility or from the following location:
http://www.adobe.com/support/downloadshttp://www.adobe.com/support/downloads
References
Adobe Acrobat / Adobe Reader Local Privilege Escalation Vulnerability
References:
References: