Adobe Acrobat JavaScript Parsing Engine Arbitrary Code Execution Vulnerability
BID:7567
Info
Adobe Acrobat JavaScript Parsing Engine Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 7567 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2003 12:00AM |
| Updated: | May 07 2003 12:00AM |
| Credit: | This vulnerability has been disclosed by the vendor. |
| Vulnerable: |
Adobe Acrobat 5.0.5 Adobe Acrobat 5.0 |
| Not Vulnerable: |
Adobe Acrobat 6.0 |
Discussion
Adobe Acrobat JavaScript Parsing Engine Arbitrary Code Execution Vulnerability
Adobe Acrobat Full has been reported prone to an input validation vulnerability.
It has been reported that this issue presents itself as a flaw in the Adobe JavaScript parsing engine. An attacker may craft a malicious PDF file embedding JavaScript code that instructs Acrobat to write attacker supplied code into the users 'Plug-ins' folder. The arbitrary code contained in the malicious plugin would be executed in the context of the user running Adobe every time the vulnerable application is launched.
It should be noted that Adobe have reported that Acrobat Reader is not affected.
Adobe Acrobat Full has been reported prone to an input validation vulnerability.
It has been reported that this issue presents itself as a flaw in the Adobe JavaScript parsing engine. An attacker may craft a malicious PDF file embedding JavaScript code that instructs Acrobat to write attacker supplied code into the users 'Plug-ins' folder. The arbitrary code contained in the malicious plugin would be executed in the context of the user running Adobe every time the vulnerable application is launched.
It should be noted that Adobe have reported that Acrobat Reader is not affected.
Exploit / POC
Adobe Acrobat JavaScript Parsing Engine Arbitrary Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Adobe Acrobat JavaScript Parsing Engine Arbitrary Code Execution Vulnerability
Solution:
The vendor has released a patch for Acrobat 5.0.5 to address this issue. Acrobat 5.0 customers are advised to download and install the Acrobat 5.0.5 update before applying the patch.
Adobe Acrobat 5.0.5
Solution:
The vendor has released a patch for Acrobat 5.0.5 to address this issue. Acrobat 5.0 customers are advised to download and install the Acrobat 5.0.5 update before applying the patch.
Adobe Acrobat 5.0.5
References
Adobe Acrobat JavaScript Parsing Engine Arbitrary Code Execution Vulnerability
References:
References: