Vulnerability Note VU#184820
Adobe Acrobat does not adequately validate Acrobat JavaScript
Overview
Adobe Acrobat contains a vulnerability in its JavaScript parsing engine that could allow an attacker to place arbitrary files on the local file system.
Description
Different versions of Adobe Acrobat software can create, modify, and read Portable Document Format (PDF) files. Acrobat JavaScript implements PDF-specific objects, methods, and properties and provides functionality similar to that of HTML client JavaScript. More information about Acrobat JavaScript is available from Acrobat 5 JavaScript Training site and in the Acrobat JavaScript Object Specification. A vulnerability in the way Acrobat 5 validates JavaScript in PDF files could allow arbitrary files to be written to any location on the local file system that is writeable by the user running Acrobat. From the Adobe Acrobat 5.0.5 Security, Accessibility, and Forms patch:
|
Impact
An attacker could cause arbitrary files to be written to the local file system within the scope of the users' permissions. |
Solution
|
|
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Adobe Systems Incorporated | Vulnerable | - | 10 Jul 2003 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.cert.org/other_sources/viruses.html
- http://www.adobe.com/support/downloads/detail.jsp?ftpID=2121
- http://securityresponse.symantec.com/avcenter/venc/data/w32.yourde.html
- http://vil.nai.com/vil/content/v_100269.htm
- http://partners.adobe.com/asn/developer/training/acrobat/javascript/main.html
- http://partners.adobe.com/asn/acrobat/docs.jsp
- http://partners.adobe.com/asn/developer/pdfs/tn/5186AcroJS.pdf
Credit
This vulnerability was reported by John Landwehr of Adobe Systems Inc.
This document was written by Art Manion.
Other Information
- CVE IDs: CAN-2003-0284
- Date Public: 30 Apr 2003
- Date First Published: 13 May 2003
- Date Last Updated: 10 Jul 2003
- Severity Metric: 4.65
- Document Revision: 35
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.
This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify