Adobe Acrobat Viewer ActiveX Buffer Overflow Vulnerability
BID:666
Info
Adobe Acrobat Viewer ActiveX Buffer Overflow Vulnerability
| Bugtraq ID: | 666 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Yes |
| Published: | Sep 27 1999 12:00AM |
| Updated: | Sep 27 1999 12:00AM |
| Credit: | This vulnerability was identified and posted to the Bugtraq Mailing List by Shane Hird <[email protected]>. |
| Vulnerable: |
Adobe Acrobat ActiveX Control 1.3.188 |
| Not Vulnerable: |
Adobe Acrobat ActiveX Control 2.0.100 |
Discussion
Adobe Acrobat Viewer ActiveX Buffer Overflow Vulnerability
There is a buffer overflow in the 1.3.188 version of the Adobe Acrobat ActiveX control (pdf.ocx) that ships with Acrobat Viewer 4.0. This ActiveX control is marked 'Safe for Scripting' within Internet Explorer 4.X. Arbitrary commands may be executed if the ActiveX control is run in a malicious manner
There is a buffer overflow in the 1.3.188 version of the Adobe Acrobat ActiveX control (pdf.ocx) that ships with Acrobat Viewer 4.0. This ActiveX control is marked 'Safe for Scripting' within Internet Explorer 4.X. Arbitrary commands may be executed if the ActiveX control is run in a malicious manner
Exploit / POC
Adobe Acrobat Viewer ActiveX Buffer Overflow Vulnerability
This code comes from Shane Hird's <[email protected]> post to Bugtraq.
This code comes from Shane Hird's <[email protected]> post to Bugtraq.
Solution / Fix
Adobe Acrobat Viewer ActiveX Buffer Overflow Vulnerability
Solution:
This issue has been corrected in the ActiveX control that ships with Acrobat 4.05 and later, available from:
http://www.adobe.com/products/acrobat/readstep.html
Solution:
This issue has been corrected in the ActiveX control that ships with Acrobat 4.05 and later, available from:
http://www.adobe.com/products/acrobat/readstep.html