|
|
|
Vulnerability Note VU#253024Adobe Acrobat Reader for UNIX contains a buffer overflow in mailListIsPdf()OverviewA buffer overflow in Adobe Acrobat Reader for UNIX could allow a remote attacker to execute arbitrary code.I. DescriptionAdobe Acrobat Reader is an application that allows users to view PDF (Portable Document Format) files. Acrobat Reader for UNIX (Linux, Sun Solaris SPARC, IBM AIX, or HP-UX) contains a buffer overflow in the mailListIsPdf() function. This function determines if the specified input file is an email message containing a PDF attachment. When parsing the email message, this function unsafely copies user-supplied data to a fixed size buffer.II. ImpactAn attacker could execute arbitrary code with privileges of the local user. Remote exploitation could be possible by attaching a specially crafted PDF to an email message.III. SolutionUpgrade Acrobat ReaderThis issue is resolved in Acrobat Reader 5.0.10 for UNIX.
References
This vulnerability was reported by Greg MacManus. This document was written by Will Dormann, based on the information provided in the iDEFENSE Security Advisory 12.14.04 .
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||