NOS Microsystems getPlus Download Manager Unauthorized Access Vulnerability
BID:32103
Info
NOS Microsystems getPlus Download Manager Unauthorized Access Vulnerability
| Bugtraq ID: | 32103 |
| Class: | Design Error |
| CVE: |
CVE-2008-4816 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2008 12:00AM |
| Updated: | Dec 04 2008 01:02AM |
| Credit: | Reported by Adobe |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE Suse Linux Enterprise Desktop 10 SP2 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Suse Linux Enterprise Desktop 10 SuSE SUSE Linux Enterprise 10 SP2 DEBUGINFO SuSE SUSE Linux Enterprise 10 SP1 DEBUGINFO SuSE SUSE Linux Enterprise 10 SP1 DEBUGINFO SuSE Linux Enterprise Server 10.SP2 SP SuSE Linux Enterprise Server 10.SP1 SuSE Linux Enterprise Server 10 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc64 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. SUSE Linux Enterprise Server RT Solution 10 0 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. openSUSE 10.1 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 9 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 X86 64 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 X86 64 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Enterprise Desktop 10 SP2 S.u.S.E. Linux Enterprise Desktop 10 SP2 S.u.S.E. Linux Enterprise Desktop 10 SP1 NOS Microsystems getPlus Download Manager 0 Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 201i Nortel Networks CallPilot 1005r Nortel Networks CallPilot 1002rp Adobe Acrobat Professional 8.1.2 Adobe Acrobat Professional 8.1.1 Adobe Acrobat Professional 7.0.9 Adobe Acrobat Professional 7.0.8 Adobe Acrobat Professional 7.0.7 Adobe Acrobat Professional 7.0.6 Adobe Acrobat Professional 7.0.5 Adobe Acrobat Professional 7.0.4 Adobe Acrobat Professional 7.0.3 Adobe Acrobat Professional 7.0.2 Adobe Acrobat Professional 7.0.1 Adobe Acrobat Professional 7.0 Adobe Acrobat Professional 8.1.2 Security Updat Adobe Acrobat Professional 8.1 Adobe Acrobat Professional 8.0 Adobe Acrobat Professional 7.1 Adobe Acrobat Professional 6.0 Adobe Acrobat 3D 8.1.2 Adobe Acrobat 3D 0 |
| Not Vulnerable: |
Adobe Reader 8.1.3 Adobe Reader 9.0 Adobe Acrobat Professional 8.1.3 Adobe Acrobat 3D 8.1.3 |
Discussion
NOS Microsystems getPlus Download Manager Unauthorized Access Vulnerability
NOS Microsystems getPlus Download Manager is prone to a security vulnerability that may allow unauthorized modifications of internet options on affected computers.
Successfully exploiting this issue may allow attackers to modify internet configuration settings, which may lead to other attacks.
The following applications use the getPlus Download Manager:
Adobe Acrobat Professional
Adobe Acrobat Reader
NOS Microsystems getPlus Download Manager is prone to a security vulnerability that may allow unauthorized modifications of internet options on affected computers.
Successfully exploiting this issue may allow attackers to modify internet configuration settings, which may lead to other attacks.
The following applications use the getPlus Download Manager:
Adobe Acrobat Professional
Adobe Acrobat Reader
Exploit / POC
NOS Microsystems getPlus Download Manager Unauthorized Access Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NOS Microsystems getPlus Download Manager Unauthorized Access Vulnerability
Solution:
Adobe has fixed this issue in the latest versions of Acrobat and Reader. Please see the references for more information.
Solution:
Adobe has fixed this issue in the latest versions of Acrobat and Reader. Please see the references for more information.
References
NOS Microsystems getPlus Download Manager Unauthorized Access Vulnerability
References:
References:
- Adobe Homepage (Adobe)
- getPlus Download Manager Homepage (NOS Microsystems)
- Security Update available for Adobe Reader 8 and Acrobat 8 (Adobe)
- Nortel Response to Adobe Vulnerability Identifier APSB08-19 (Nortel Networks)