NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Security Fixes and Improvements

Security Fixes and Improvements


Adobe Reader and Acrobat 8 Plagued by Remote Code Execution Vulnerabilities

Adobe released an advisory and patches for all of them

By Lucian Constantin, Web News Editor

5th of November 2008, 13:08 GMT

Adjust text size:


Multiple Adobe Reader and Acrobat vulnerabilities disclosed
Enlarge picture
Adobe has announced the existence of no less than five local and remote code execution vulnerabilities in the 8.1.2 and earlier versions of Adobe Reader and Acrobat. Security patches have been released for all of them along with an advisory, which also includes a privilege escalation and a denial of service vulnerability.

One of the most critical and exploitable vulnerabilities was discovered by Damian Frizza from the CORE IMPACT Exploit Writers Team at Core Security Technologies and is identified as CVE-2008-2992. The vulnerability consists of a buffer overflow occurring during execution of the JavaScript printf function. Successful exploitation allows an attacker to remotely execute arbitrary code on the system under the privileges of the current user.

This can be achieved by serving a maliciously crafted PDF file to a user. The PDF file would be required to have the JavaScript exploit code embedding, so disabling JavaScript in the Reader or Acrobat applications is a workaround. However, this would also prevent legit PDFs that contain JavaScript from displaying and functioning correctly.

“As with many of today’s ubiquitous client-side applications, the sheer complexity of Adobe Reader creates a broad surface for potential vulnerabilities and, in this case, Adobe’s inclusion of a fully fledged JavaScript engine introduces the same types of implementation bugs commonly found in such sophisticated client-side programs,” noted Ivan Arce, Chief Technology Officer at Core Security Technologies.

This vulnerability was discovered while investigating an already known bug in Foxit Reader, another PDF viewing application. “While investigating the feasibility of exploiting the vulnerability previously disclosed in Foxit Reader (CVE-2008-1104) we found that Adobe Reader was affected by the same bug,” is noted in the CORE advisory.

The other vulnerabilities disclosed by Adobe in their advisory are identified in the Common Vulnerabilities and Exposures List as CVE-2008-4812, CVE-2008-4813, CVE-2008-4814, CVE-2008-4815, CVE-2008-4816, CVE-2008-4817 and CVE-2008-2549. “Adobe is not aware of any reports of these issues being exploited in the wild,” wrote the Product Security Incident Response Team (PSIRT) on their official blog. "These issues do not apply to Adobe Reader 9 or Acrobat 9, so no action is required for customers who already have Adobe Reader 9 or Acrobat 9 installed," they add.

TAGS:

Adobe Reader | Adobe Acrobat | Buffer overflow | Remote code execution | Patch
Read by 1,514 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.0/5) 1 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Adobe Fixes Clickjacking and Clipboard Hijacking Vulnerabilities

Web Users at Risk of Being Spied Through Their Own Webcams and Microphones

Adobe Searches for Solutions in the Clipboard Attack Case

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM