Adobe Acrobat and Reader Multiple Arbitrary Code Execution and Security Vulnerabilities
BID:27641
Info
Adobe Acrobat and Reader Multiple Arbitrary Code Execution and Security Vulnerabilities
| Bugtraq ID: | 27641 |
| Class: | Unknown |
| CVE: |
CVE-2008-0655 CVE-2007-5659 CVE-2007-5663 CVE-2007-5666 CVE-2008-0667 CVE-2008-0726 CVE-2008-2042 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2008 12:00AM |
| Updated: | Jul 07 2008 11:39PM |
| Credit: | The vendor disclosed these issues. Paul Craig reported the '.joboptions' vulnerability to the vendor. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise Desktop 10 SP1 Sun Solaris 10 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.1 RedHat Enterprise Linux Extras 4 RedHat Enterprise Linux Extras 3 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Desktop Supplementary 5 client Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Self-Service - Peri Application Rel 3.0 Nortel Networks Self-Service 0 Nortel Networks Peri Application 0 Nortel Networks Media Processing Svr 500 Rel 3.0 Nortel Networks Media Processing Svr 1000 Rel 3.0 Nortel Networks Media Processing Svr 100 0 Gentoo Linux 2007.0 Gentoo Linux Avaya Interactive Response 3.0 Avaya Interactive Response 2.0 Adobe Reader 8.1.1 Adobe Reader 7.0.9 Adobe Reader 7.0.8 Adobe Reader 7.0.8 Adobe Reader 7.0.7 Adobe Reader 7.0.6 Adobe Reader 7.0.5 Adobe Reader 7.0.4 Adobe Reader 7.0.3 Adobe Reader 7.0.2 Adobe Reader 7.0.1 Adobe Reader 7.0 Adobe Reader 6.0.4 Adobe Reader 6.0.3 Adobe Reader 6.0.2 Adobe Reader 6.0.1 Adobe Reader 6.0 Adobe Reader 5.1 Adobe Reader 5.0.10 Adobe Reader 5.0.5 Adobe Reader 5.0 Adobe Reader 4.0.5 A Adobe Reader 4.0 5c Adobe Reader 4.0 5 Adobe Reader 4.0 Adobe Reader 3.0 Adobe Reader 8.1 Adobe Reader 8.0 Adobe Acrobat Standard 8.1.1 Adobe Acrobat Professional 8.1.1 Adobe Acrobat Professional 7.0.8 Adobe Acrobat Professional 7.0.7 Adobe Acrobat Professional 7.0.6 Adobe Acrobat Professional 7.0.5 Adobe Acrobat Professional 7.0.4 Adobe Acrobat Professional 7.0.3 Adobe Acrobat Professional 7.0.2 Adobe Acrobat Professional 7.0.1 Adobe Acrobat Professional 7.0 Adobe Acrobat Professional 8.1 Adobe Acrobat Professional 8.0 Adobe Acrobat 3D 0 |
| Not Vulnerable: |
Adobe Reader 8.1.2 Adobe Reader 7.1 Adobe Acrobat Standard 8.1.2 Adobe Acrobat Standard 7.1 Adobe Acrobat Professional 8.1.2 Adobe Acrobat Professional 7.1 |
Discussion
Adobe Acrobat and Reader Multiple Arbitrary Code Execution and Security Vulnerabilities
Adobe Acrobat and Reader are prone to multiple arbitrary remote code-execution and security vulnerabilities.
Attackers can exploit these issues to execute arbitrary code in the context of the user running the affected application. Other attacks are also possible.
Versions prior to Adobe Acrobat and Adobe Reader 8.1.2 are vulnerable to these issues.
Adobe Acrobat and Reader are prone to multiple arbitrary remote code-execution and security vulnerabilities.
Attackers can exploit these issues to execute arbitrary code in the context of the user running the affected application. Other attacks are also possible.
Versions prior to Adobe Acrobat and Adobe Reader 8.1.2 are vulnerable to these issues.
Exploit / POC
Adobe Acrobat and Reader Multiple Arbitrary Code Execution and Security Vulnerabilities
An exploit and proof-of-concept exploit are available to members of the Immunity Partners Program:
https://www.immunityinc.com/downloads/immpartners/acrobat.tgz
https://www.immunityinc.com/downloads/immpartners/acrobatfull.tgz
NOTE: Reports indicate that at the 'Collab.collectEmailInfo()' function issue tracked by CVE-2007-5659 is being exploited in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept code is also available:
An exploit and proof-of-concept exploit are available to members of the Immunity Partners Program:
https://www.immunityinc.com/downloads/immpartners/acrobat.tgz
https://www.immunityinc.com/downloads/immpartners/acrobatfull.tgz
NOTE: Reports indicate that at the 'Collab.collectEmailInfo()' function issue tracked by CVE-2007-5659 is being exploited in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept code is also available:
Solution / Fix
Adobe Acrobat and Reader Multiple Arbitrary Code Execution and Security Vulnerabilities
Solution:
Adobe has released updates to address these issues. Please see the references for information on obtaining and applying fixes.
Adobe Reader 8.0
Adobe Reader 8.1
Adobe Acrobat 3D 0
Adobe Reader 7.0
Adobe Reader 7.0.1
Adobe Reader 7.0.2
Adobe Reader 7.0.3
Adobe Reader 7.0.4
Adobe Reader 7.0.5
Adobe Reader 7.0.6
Adobe Reader 7.0.7
Adobe Reader 7.0.8
Adobe Reader 7.0.8
Adobe Reader 7.0.9
Adobe Reader 8.1.1
Solution:
Adobe has released updates to address these issues. Please see the references for information on obtaining and applying fixes.
Adobe Reader 8.0
-
Adobe AcrobatUpd812_all_incr.msp
Windows
http://www.adobe.com/support/downloads/thankyou.jsp?ftpID=3849&fileID= 3603 -
Adobe AcroProUpd812_all.dmg
Mac OSX
http://www.adobe.com/support/downloads/thankyou.jsp?ftpID=3856&fileID= 3602 -
Adobe Adobe Reader 8.1.2
Linux
http://www.adobe.com/products/acrobat/readstep2_servefile.html
Adobe Reader 8.1
-
Adobe AcrobatUpd812_all_incr.msp
Windows
http://www.adobe.com/support/downloads/thankyou.jsp?ftpID=3849&fileID= 3603 -
Adobe AcroProUpd812_all.dmg
Mac OSX
http://www.adobe.com/support/downloads/thankyou.jsp?ftpID=3856&fileID= 3602 -
Adobe Adobe Reader 8.1.2
Linux
http://www.adobe.com/products/acrobat/readstep2_servefile.html
Adobe Acrobat 3D 0
-
Adobe AcrobatUpd812_all_incr.msp
Windows
http://www.adobe.com/support/downloads/thankyou.jsp?ftpID=3850&fileID= 3606
Adobe Reader 7.0
-
Adobe Adobe Reader 8.1.2
Linux
http://www.adobe.com/products/acrobat/readstep2_servefile.html
Adobe Reader 7.0.1
-
Adobe Adobe Reader 8.1.2
Linux
http://www.adobe.com/products/acrobat/readstep2_servefile.html
Adobe Reader 7.0.2
-
Adobe Adobe Reader 8.1.2
Linux
http://www.adobe.com/products/acrobat/readstep2_servefile.html
Adobe Reader 7.0.3
-
Adobe Adobe Reader 8.1.2
Linux
http://www.adobe.com/products/acrobat/readstep2_servefile.html
Adobe Reader 7.0.4
-
Adobe Adobe Reader 8.1.2
Linux
http://www.adobe.com/products/acrobat/readstep2_servefile.html
Adobe Reader 7.0.5
-
Adobe Adobe Reader 8.1.2
Linux
http://www.adobe.com/products/acrobat/readstep2_servefile.html
Adobe Reader 7.0.6
-
Adobe Adobe Reader 8.1.2
Linux
http://www.adobe.com/products/acrobat/readstep2_servefile.html
Adobe Reader 7.0.7
-
Adobe Adobe Reader 8.1.2
Linux
http://www.adobe.com/products/acrobat/readstep2_servefile.html
Adobe Reader 7.0.8
-
Adobe Adobe Reader 8.1.2
Linux
http://www.adobe.com/products/acrobat/readstep2_servefile.html
Adobe Reader 7.0.8
-
Adobe Adobe Reader 8.1.2
Linux
http://www.adobe.com/products/acrobat/readstep2_servefile.html
Adobe Reader 7.0.9
-
Adobe Adobe Reader 8.1.2
Linux
http://www.adobe.com/products/acrobat/readstep2_servefile.html
Adobe Reader 8.1.1
-
Adobe AcrobatUpd812_all_incr.msp
Windows
http://www.adobe.com/support/downloads/thankyou.jsp?ftpID=3849&fileID= 3603 -
Adobe AcroProUpd812_all.dmg
Mac OSX
http://www.adobe.com/support/downloads/thankyou.jsp?ftpID=3856&fileID= 3602 -
Adobe Adobe Reader 8.1.2
Linux
http://www.adobe.com/products/acrobat/readstep2_servefile.html
References
Adobe Acrobat and Reader Multiple Arbitrary Code Execution and Security Vulnerabilities
References:
References:
- Adobe Reader 8 Homepage (Adobe)
- Adobe Reader 8.1.2 Release Notes (Adobe)
- Adobe Reader Download Page (Adobe)
- Attacking Embedded Languages ([email protected])
- Technical Cyber Security Alert TA08-043A (US-CERT)
- [Advisory Update]Adobe Reader/Acrobat Remote PDF (cocoruder)
- Adobe Acrobat Professional Javascript For PDF Security Feature Bypass and Memory (cocoruder)
- Adobe Reader/Acrobat Remote PDF Print Silently Vulnerability (cocoruder
) - iDefense Security Advisory 02.08.08: Adobe Reader and Acrobat JavaScript Insecur (iDefense Labs
) - iDefense Security Advisory 02.08.08: Adobe Reader and Acrobat Multiple Stack-bas (iDefense Labs
) - iDefense Security Advisory 02.08.08: Adobe Reader Security Provider Unsafe Libar (iDefense Labs
) - Malformed Acrobat Distiller 8 .joboptions ("Paul Craig"
) - Adobe Reader and Acrobat JavaScript Insecure Method Exposure Vulnerability (iDefense)
- Adobe Reader and Acrobat Multiple Stack-based Buffer Overflow Vulnerabilities (iDefense)
- Adobe Reader Security Provider Unsafe Libary Path Vulnerability (iDefense)
- APSA08-01 Security update available for Adobe Reader and Acrobat 8 (Adobe)
- APSB08-13 Security Updates available for Adobe Reader and Acrobat 7 and 8 (Adobe)
- ASA-2008-281 Multiple Security Vulnerabilities in the Adobe Reader may lead to E (Avaya)
- Malformed .joboptions File Effecting Adobe Acrobat Distiller v8 (Security-Assessment.com)
- Nortel response to Adobe Advisory APSB08-13 (Nortel Networks)
- Nortel Response to Adobe Reader Vulnerabilities (APSA08-01) (Nortel Networks)
- RHSA-2008:0144-5 acroread security update (Red Hat)
- Solution 239286: Multiple Security Vulnerabilities in the Adobe Reader may lead (Sun Microsystems)
- Vulnerability Note VU#140129 Adobe Reader EScript.api arbitrary code execution (US-CERT)
- Vulnerability Note VU#666281 Adobe JavaScript methods buffer overflow vulnerabil (US-CERT)
- ZDI-08-004 Adobe Acrobat Javascript for PDF Integer Overflow Vulnerability (ZDI)