Adobe eBook Reader File Transfer Authorization Voucher Weak Algorithm Vulnerability
BID:5358
Info
Adobe eBook Reader File Transfer Authorization Voucher Weak Algorithm Vulnerability
| Bugtraq ID: | 5358 |
| Class: | Design Error |
| CVE: |
CVE-2002-1017 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 30 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Published by ElcomSoft Co.Ltd. <[email protected]>. |
| Vulnerable: |
Adobe eBook Reader for Windows 2.2 Adobe eBook Reader for Windows 2.1 Adobe eBook Reader for Mac OS 9 2.2 Adobe eBook Reader for Mac OS 9 2.1 |
| Not Vulnerable: | |
Discussion
Adobe eBook Reader File Transfer Authorization Voucher Weak Algorithm Vulnerability
Adobe eBook Reader is a client side application which is able to view Adobe eBooks, available for Microsoft Windows and Macintosh OS 9.
Reportedly, an eBook may be transferred to a different computer by backing up the book content and a number of datafiles. When the eBook is opened, however, the user will be prompted for a new authorization voucher, and given a challenge string.
It has been reported that the encryption scheme used for this challenge / response cycle is fundamentally flawed. Allegedly, both the challenge and response can be computed using commonly available cryptographic algorithms, based on secret information stored within the eBook Reader executable file.
A malicious user with details on the algorith may computer the correct response without vendor interaction.
Adobe eBook Reader is a client side application which is able to view Adobe eBooks, available for Microsoft Windows and Macintosh OS 9.
Reportedly, an eBook may be transferred to a different computer by backing up the book content and a number of datafiles. When the eBook is opened, however, the user will be prompted for a new authorization voucher, and given a challenge string.
It has been reported that the encryption scheme used for this challenge / response cycle is fundamentally flawed. Allegedly, both the challenge and response can be computed using commonly available cryptographic algorithms, based on secret information stored within the eBook Reader executable file.
A malicious user with details on the algorith may computer the correct response without vendor interaction.
Solution / Fix
Adobe eBook Reader File Transfer Authorization Voucher Weak Algorithm Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Adobe eBook Reader File Transfer Authorization Voucher Weak Algorithm Vulnerability
References:
References:
- eBook Reader Homepage (Adobe)