Adobe Acrobat and Reader PDF File Handling JBIG2 Image Remote Code Execution Vulnerability
BID:33751
Info
Adobe Acrobat and Reader PDF File Handling JBIG2 Image Remote Code Execution Vulnerability
| Bugtraq ID: | 33751 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-0658 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 19 2009 12:00AM |
| Updated: | Mar 19 2015 08:46AM |
| Credit: | Symantec |
| Vulnerable: |
Turbolinux Client 2008 SuSE SUSE Linux Enterprise Desktop 11 SuSE SUSE Linux Enterprise Desktop 10 SP2 SuSE openSUSE 10.3 Sun Solaris 10_sparc S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Desktop 10 Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks CallPilot 703t Nortel Networks CallPilot 600r Nortel Networks CallPilot 201i Nortel Networks CallPilot 1005r Nortel Networks CallPilot 1002rp Gentoo Linux Adobe Reader 8.1.3 Adobe Reader 8.1.2 Adobe Reader 8.1.1 Adobe Reader 7.0.9 Adobe Reader 7.0.8 Adobe Reader 7.0.7 Adobe Reader 7.0.6 Adobe Reader 7.0.5 Adobe Reader 7.0.4 Adobe Reader 7.0.3 Adobe Reader 7.0.2 Adobe Reader 7.0.1 Adobe Reader 7.0 Adobe Reader 9 Adobe Reader 8.1.2 Security Updat Adobe Reader 8.1 Adobe Reader 8.0 Adobe Reader 7.1 Adobe Acrobat Standard 8.1.3 Adobe Acrobat Standard 8.1.2 Adobe Acrobat Standard 8.1.1 Adobe Acrobat Standard 7.0.8 Adobe Acrobat Standard 7.0.7 Adobe Acrobat Standard 7.0.6 Adobe Acrobat Standard 7.0.5 Adobe Acrobat Standard 7.0.4 Adobe Acrobat Standard 7.0.3 Adobe Acrobat Standard 7.0.2 Adobe Acrobat Standard 7.0.1 Adobe Acrobat Standard 7.0 Adobe Acrobat Standard 9 Adobe Acrobat Standard 8.1 Adobe Acrobat Standard 8.0 Adobe Acrobat Standard 7.1 Adobe Acrobat Reader (UNIX) 7.0.1 Adobe Acrobat Reader (UNIX) 7.0 Adobe Acrobat Professional 8.1.3 Adobe Acrobat Professional 8.1.2 Adobe Acrobat Professional 8.1.1 Adobe Acrobat Professional 7.0.9 Adobe Acrobat Professional 7.0.8 Adobe Acrobat Professional 7.0.7 Adobe Acrobat Professional 7.0.6 Adobe Acrobat Professional 7.0.5 Adobe Acrobat Professional 7.0.4 Adobe Acrobat Professional 7.0.3 Adobe Acrobat Professional 7.0.2 Adobe Acrobat Professional 7.0.1 Adobe Acrobat Professional 7.0 Adobe Acrobat Professional 9 Adobe Acrobat Professional 8.1.2 Security Updat Adobe Acrobat Professional 8.1 Adobe Acrobat Professional 8.0 Adobe Acrobat Professional 7.1 Adobe Acrobat 7.0.3 Adobe Acrobat 7.0.2 Adobe Acrobat 7.0.1 Adobe Acrobat 7.0 |
| Not Vulnerable: |
Adobe Reader 8.1.4 Adobe Reader 7.1.1 Adobe Reader 9.1 Adobe Acrobat Standard 8.1.4 Adobe Acrobat Standard 7.1.1 Adobe Acrobat Standard 9.1 Adobe Acrobat Professional 8.1.4 Adobe Acrobat Professional 7.1.1 Adobe Acrobat Professional 9.1 |
Discussion
Adobe Acrobat and Reader PDF File Handling JBIG2 Image Remote Code Execution Vulnerability
Adobe Acrobat and Reader are prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the application or crash the application, denying service to legitimate users.
The issue affects Reader and Acrobat 9, 8.1.3 and prior, and 7.
UPDATE (February 24, 2009): Further reports suggest that this issue affects the vulnerable applications running on Apple Mac OS X and various Linux-based operating systems.
Adobe Acrobat and Reader are prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the application or crash the application, denying service to legitimate users.
The issue affects Reader and Acrobat 9, 8.1.3 and prior, and 7.
UPDATE (February 24, 2009): Further reports suggest that this issue affects the vulnerable applications running on Apple Mac OS X and various Linux-based operating systems.
Exploit / POC
Adobe Acrobat and Reader PDF File Handling JBIG2 Image Remote Code Execution Vulnerability
Symantec captured an attempt to exploit this issue as a part of a targeted attack in the wild via 'Trojan.Pidief.E'.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following commercial exploit is available for Immunity CANVAS:
https://www.immunityinc.com/downloads/immpartners/acrobat_jbig.tar.gz
The following proofs of concept and exploit are available:
Symantec captured an attempt to exploit this issue as a part of a targeted attack in the wild via 'Trojan.Pidief.E'.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following commercial exploit is available for Immunity CANVAS:
https://www.immunityinc.com/downloads/immpartners/acrobat_jbig.tar.gz
The following proofs of concept and exploit are available:
Solution / Fix
Adobe Acrobat and Reader PDF File Handling JBIG2 Image Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Adobe Reader 9.0
Adobe Acrobat Professional 9
Adobe Reader 7.1
S.u.S.E. openSUSE 11.0
Adobe Reader 8.0
S.u.S.E. openSUSE 11.1
Adobe Reader 8.1
Adobe Acrobat Standard 9
Adobe Reader 7.0
Adobe Reader 7.0.1
Adobe Reader 7.0.2
Adobe Reader 7.0.3
Adobe Reader 7.0.4
Adobe Reader 7.0.5
Adobe Reader 7.0.6
Adobe Reader 7.0.7
Adobe Reader 7.0.8
Adobe Reader 7.0.9
Adobe Reader 8.1.1
Adobe Reader 8.1.2
Adobe Reader 8.1.3
Solution:
Updates are available. Please see the references for more information.
Adobe Reader 9.0
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
Adobe Acrobat Professional 9
-
Adobe AcroProStdUpd910_T1T2_incr.msp
http://ardownload.adobe.com/pub/adobe/acrobat/win/9.x/9.1/misc/AcroPro StdUpd910_T1T2_incr.msp
Adobe Reader 7.1
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
S.u.S.E. openSUSE 11.0
-
S.u.S.E. acroread-8.1.4-0.1.i586.rpm
http://download.opensuse.org/update/11.0/rpm/i586/acroread-8.1.4-0.1.i 586.rpm
Adobe Reader 8.0
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
S.u.S.E. openSUSE 11.1
-
S.u.S.E. acroread-8.1.4-0.1.1.i586.rpm
http://download.opensuse.org/update/11.1/rpm/i586/acroread-8.1.4-0.1.1 .i586.rpm
Adobe Reader 8.1
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
Adobe Acrobat Standard 9
-
Adobe AcroProStdUpd910_T1T2_incr.msp
http://ardownload.adobe.com/pub/adobe/acrobat/win/9.x/9.1/misc/AcroPro StdUpd910_T1T2_incr.msp
Adobe Reader 7.0
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
Adobe Reader 7.0.1
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
Adobe Reader 7.0.2
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
Adobe Reader 7.0.3
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
Adobe Reader 7.0.4
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
Adobe Reader 7.0.5
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
Adobe Reader 7.0.6
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
Adobe Reader 7.0.7
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
Adobe Reader 7.0.8
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
Adobe Reader 7.0.9
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
Adobe Reader 8.1.1
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
Adobe Reader 8.1.2
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
Adobe Reader 8.1.3
-
Adobe AdbeRdr910_en_US_Std.exe
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.1/enu/AdbeRdr91 0_en_US_Std.exe
References
Adobe Acrobat and Reader PDF File Handling JBIG2 Image Remote Code Execution Vulnerability
References:
References:
- /JBIG2Decode �??Look Mommy, No Hands!�?� (Didier Stevens)
- /JBIG2Decode Trigger Trio (Didier Stevens)
- [Black Security]: Adobe Acrobat/Reader Universal Exploit : APSB09-01 (aka CVE-20 (Black Security)
- Adobe Homepage (Adobe)
- Adobe Reader and Acrobat 9.1 update available (Adobe)
- Adobe Reader and Acrobat issue (Adobe)
- 256788 Multiple Security Vulnerabilities in Adobe Reader for Solaris 10 (Sun)
- APSA09-01 - Buffer overflow issue in versions 9.0 and earlier of Adobe Reader an (Adobe)
- APSB09-03 - Security Updates available for Adobe Reader 9 and Acrobat 9 (Adobe)
- APSB09-04 Security Updates available for Adobe Reader and Acrobat (Adobe)
- Nortel Response to Adobe APSA09-01 - Buffer overflow issue in v9.0 and earlier o (Nortel Networks)
- Nortel response to Sun Alerts 256788 and 262668 on Solaris 10 Potential Vulnerab (Nortel Networks)
- Security Updates available for Adobe Reader 9 and Acrobat 9 (Adobe)
- Vulnerability Note VU#905281 Adobe Reader and Acrobat memory corruption vulnerab (US-CERT)