Adobe Acrobat and Reader Collab 'getIcon()' JavaScript Method Remote Code Execution Vulnerability
BID:34169
Info
Adobe Acrobat and Reader Collab 'getIcon()' JavaScript Method Remote Code Execution Vulnerability
| Bugtraq ID: | 34169 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0927 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2009 12:00AM |
| Updated: | Mar 19 2015 08:30AM |
| Credit: | Tenable Network Security reported through TippingPoint's Zero Day Initiative |
| Vulnerable: |
SuSE Suse Linux Enterprise Desktop 11 SuSE Suse Linux Enterprise Desktop 10 SP2 SuSE Linux Desktop 10 Sun Solaris 10_sparc S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 S.u.S.E. Novell Linux Desktop 9.0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service - CCSS7 0 Gentoo Linux Adobe Reader 8.1.2 Adobe Reader 8.1.1 Adobe Reader 7.0.9 Adobe Reader 7.0.8 Adobe Reader 7.0.7 Adobe Reader 7.0.6 Adobe Reader 7.0.5 Adobe Reader 7.0.4 Adobe Reader 7.0.3 Adobe Reader 7.0.2 Adobe Reader 7.0.1 Adobe Reader 7.0 Adobe Reader 9.0 Adobe Reader 8.1.2 Security Updat Adobe Reader 8.1 Adobe Reader 8.0 Adobe Reader 7.1 Adobe Acrobat Standard 8.1.2 Adobe Acrobat Standard 8.1.1 Adobe Acrobat Standard 7.0.8 Adobe Acrobat Standard 7.0.7 Adobe Acrobat Standard 7.0.6 Adobe Acrobat Standard 7.0.5 Adobe Acrobat Standard 7.0.4 Adobe Acrobat Standard 7.0.3 Adobe Acrobat Standard 7.0.2 Adobe Acrobat Standard 7.0.1 Adobe Acrobat Standard 7.0 Adobe Acrobat Standard 9 Adobe Acrobat Standard 8.1 Adobe Acrobat Standard 8.0 Adobe Acrobat Standard 7.1 Adobe Acrobat Professional 8.1.2 Adobe Acrobat Professional 8.1.1 Adobe Acrobat Professional 7.0.9 Adobe Acrobat Professional 7.0.8 Adobe Acrobat Professional 7.0.7 Adobe Acrobat Professional 7.0.6 Adobe Acrobat Professional 7.0.5 Adobe Acrobat Professional 7.0.4 Adobe Acrobat Professional 7.0.3 Adobe Acrobat Professional 7.0.2 Adobe Acrobat Professional 7.0.1 Adobe Acrobat Professional 7.0 Adobe Acrobat Professional 9 Adobe Acrobat Professional 8.1.2 Security Updat Adobe Acrobat Professional 8.1 Adobe Acrobat Professional 8.0 Adobe Acrobat Professional 7.1 |
| Not Vulnerable: |
Adobe Reader 8.1.3 Adobe Reader 7.1.1 Adobe Reader 9.1 Adobe Acrobat Standard 8.1.3 Adobe Acrobat Standard 7.1.1 Adobe Acrobat Standard 9.1 Adobe Acrobat Professional 8.1.3 Adobe Acrobat Professional 7.1.1 Adobe Acrobat Professional 9.1 |
Discussion
Adobe Acrobat and Reader Collab 'getIcon()' JavaScript Method Remote Code Execution Vulnerability
Adobe Acrobat and Reader are prone to a remote code-execution vulnerability because the software fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the application or crash the application, denying service to legitimate users.
The issue affects the following:
Reader and Acrobat 7.1 and prior
Reader and Acrobat 8.1.2 and prior
Reader and Acrobat 9
UPDATE (March 24, 2009): This BID was previously titled 'Adobe Acrobat and Reader Unspecified JavaScript Method Remote Code Execution Vulnerability', but has been updated to better document the issue.
Adobe Acrobat and Reader are prone to a remote code-execution vulnerability because the software fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the application or crash the application, denying service to legitimate users.
The issue affects the following:
Reader and Acrobat 7.1 and prior
Reader and Acrobat 8.1.2 and prior
Reader and Acrobat 9
UPDATE (March 24, 2009): This BID was previously titled 'Adobe Acrobat and Reader Unspecified JavaScript Method Remote Code Execution Vulnerability', but has been updated to better document the issue.
Exploit / POC
Adobe Acrobat and Reader Collab 'getIcon()' JavaScript Method Remote Code Execution Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
UPDATE (April 6, 2009): Symantec has detected active exploit attempts of this issue in the wild.
An exploit is available in the references section of this document.
The following example exploit is available:
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
UPDATE (April 6, 2009): Symantec has detected active exploit attempts of this issue in the wild.
An exploit is available in the references section of this document.
The following example exploit is available:
Solution / Fix
Adobe Acrobat and Reader Collab 'getIcon()' JavaScript Method Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for details.
S.u.S.E. openSUSE 11.1
S.u.S.E. openSUSE 11.0
Solution:
Updates are available. Please see the references for details.
S.u.S.E. openSUSE 11.1
-
S.u.S.E. acroread-8.1.4-0.1.1.i586.rpm
http://download.opensuse.org/update/11.1/rpm/i586/acroread-8.1.4-0.1.1 .i586.rpm
S.u.S.E. openSUSE 11.0
-
S.u.S.E. acroread-8.1.4-0.1.i586.rpm
http://download.opensuse.org/update/11.0/rpm/i586/acroread-8.1.4-0.1.i 586.rpm
References
Adobe Acrobat and Reader Collab 'getIcon()' JavaScript Method Remote Code Execution Vulnerability
References:
References:
- Adobe Homepage (Adobe)
- Exploit and technical report about the Adobe Acrobat and Reader (Ivan Rodriguez Almuina)
- 256788 Multiple Security Vulnerabilities in Adobe Reader for Solaris 10 (Sun)
- APSB09-04 Security Updates available for Adobe Reader and Acrobat (Adobe)
- Nortel response to Sun Alerts 256788 and 262668 on Solaris 10 Potential Vulnerab (Nortel Networks)
- ZDI-09-014 Adobe Acrobat getIcon() Stack Overflow Vulnerability (Zero Day Initiative)