Adobe Form Designer and Adobe Form Client Multiple Buffer-Overflow Vulnerabilities
BID:28210
Info
Adobe Form Designer and Adobe Form Client Multiple Buffer-Overflow Vulnerabilities
| Bugtraq ID: | 28210 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6253 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 11 2008 12:00AM |
| Updated: | Mar 13 2008 03:41PM |
| Credit: | Will Dormann of CERT/CC is credited with the discovery of these issues. |
| Vulnerable: |
Adobe Form Designer 5.0 Adobe Form Client 5.0 |
| Not Vulnerable: | |
Discussion
Adobe Form Designer and Adobe Form Client Multiple Buffer-Overflow Vulnerabilities
Adobe Form Designer and Adobe Form Client are prone to multiple buffer-overflow vulnerabilities.
These issues affect ActiveX controls supplied with the applications and arise because the applications fail to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit these issues to execute arbitrary code in the context of an application running the control (typically Internet Explorer). Failed attacks will cause denial-of-service conditions.
Adobe Form Designer and Adobe Form Client are prone to multiple buffer-overflow vulnerabilities.
These issues affect ActiveX controls supplied with the applications and arise because the applications fail to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit these issues to execute arbitrary code in the context of an application running the control (typically Internet Explorer). Failed attacks will cause denial-of-service conditions.
Exploit / POC
Adobe Form Designer and Adobe Form Client Multiple Buffer-Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Form Designer and Adobe Form Client Multiple Buffer-Overflow Vulnerabilities
Solution:
The vendor released an advisory and patches to address these issues. Please see the references for more information.
Adobe Form Designer 5.0
Adobe Form Client 5.0
Solution:
The vendor released an advisory and patches to address these issues. Please see the references for more information.
Adobe Form Designer 5.0
-
Adobe Adobe FormDesigner 5.0 patch 5.0.5990.2008
http://download.adobe.com/pub/adobe/server/formclient/win/p_des_5_0_59 90.zip
Adobe Form Client 5.0
-
Adobe Adobe Form Client 5.0 patch 5.0.5990.2008
http://download.adobe.com/pub/adobe/server/formclient/win/p5_0_5990.zi p
References
Adobe Form Designer and Adobe Form Client Multiple Buffer-Overflow Vulnerabilities
References:
References:
- Adobe Homepage (Adobe)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vulnerability Note VU#362849 (US-CERT)
- Update available to resolve critical vulnerabilities in Adobe Form Designer 5.0 (Adobe)