Adobe AcroRead Insecure Default Font List Permissions Vulnerability
BID:3225
Info
Adobe AcroRead Insecure Default Font List Permissions Vulnerability
| Bugtraq ID: | 3225 |
| Class: | Design Error |
| CVE: |
CVE-2001-1069 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 22 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was announced by Michael Paoli <[email protected]> to Bugtraq on August 22, 2001. |
| Vulnerable: |
Adobe Acrobat Reader (UNIX) 5.0 5 Adobe Acrobat Reader (UNIX) 4.0 5 |
| Not Vulnerable: |
Adobe Acrobat Reader (UNIX) 5.0 7 Adobe Acrobat Reader (UNIX) 5.0 6 |
Discussion
Adobe AcroRead Insecure Default Font List Permissions Vulnerability
Adobe Acrobat Reader is a freely available PDF document reading utility distributed by Adobe. A problem with the program could allow local users to gain elevated privileges.
When executed, the Acrobat Reader creates a predictable file, and sets the permissions to 0666, granting world read and write access. A local attacker may use a symbolic link attack to set the permissions on any file owned by the vulnerable user, and replace executable files or scripts with trojans.
Reportedly, Acrobat Reader 5.05 creates the file as /tmp/AdobeFnt.lst.UID (including the UID of the invoking user). Acrobat Reader 4.05 creates the font list file in the user's home directory.
It has been reported that Acrobat Reader for Mac OS X does not suffer from this vulnerability.
Adobe Acrobat Reader is a freely available PDF document reading utility distributed by Adobe. A problem with the program could allow local users to gain elevated privileges.
When executed, the Acrobat Reader creates a predictable file, and sets the permissions to 0666, granting world read and write access. A local attacker may use a symbolic link attack to set the permissions on any file owned by the vulnerable user, and replace executable files or scripts with trojans.
Reportedly, Acrobat Reader 5.05 creates the file as /tmp/AdobeFnt.lst.UID (including the UID of the invoking user). Acrobat Reader 4.05 creates the font list file in the user's home directory.
It has been reported that Acrobat Reader for Mac OS X does not suffer from this vulnerability.
Solution / Fix
Adobe AcroRead Insecure Default Font List Permissions Vulnerability
Solution:
SGI has stated that IRIX 6.5 to 6.5.18 is vulnerable to this issue. Users are advised to upgrade to IRIX 6.5.19 or apply the workaround provided in the advisory.
FreeBSD has released a Security Notice FreeBSD-SN-02:05. Users of FreeBSD systems are strongly urged to upgrade their ports tree to fix various reported issues. Further information can be found in the referenced Security Notice.
This problem has is confirmed to be fixed in Acrobat Reader versions 5.06 and later. Users are advised to contact the vendor for details on upgrading to the most recent version.
Solution:
SGI has stated that IRIX 6.5 to 6.5.18 is vulnerable to this issue. Users are advised to upgrade to IRIX 6.5.19 or apply the workaround provided in the advisory.
FreeBSD has released a Security Notice FreeBSD-SN-02:05. Users of FreeBSD systems are strongly urged to upgrade their ports tree to fix various reported issues. Further information can be found in the referenced Security Notice.
This problem has is confirmed to be fixed in Acrobat Reader versions 5.06 and later. Users are advised to contact the vendor for details on upgrading to the most recent version.
References
Adobe AcroRead Insecure Default Font List Permissions Vulnerability
References:
References: