|
Adobe Acrobat Reader Arbitrary Code Execution and Unspecified Remote Denial-of-Service Vulnerability |
|
|
|
|
Written by crashoveride
|
|
Wednesday, 11 June 2008 |
Since yesterday some vulnerabilities have been reported in Adobe Reader/Acrobat, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system.
Severity Rating: High
System Affected
* Adobe Acrobat Reader 8.1.2 and prior
Overview
A vulnerability has been reported in Adobe Acrobat Reader 8.1.2 and
earlier, which could cause a denial-of-service (application crash).
Description
The vulnerability in Adobe Acrobat Reader 8.1.2 and prior allows remote
attacker to execute multiple arbitrary code. Successful exploitation
could crash the application and allows a denial-of-service via
malformed or specially crafted PDF documents.
Workarounds
* Do not open documents that originate from unknown or untrusted sources.
* Do not follow links provided by unknown or untrusted sources.
* Remove the file association with PDFs and Adobe Reader so they are not immediately executed.
References
SecurityFocus
http://www.securityfocus.com/bid/29420/info
Security Lab
http://en.securitylab.ru/nvd/354261.php
Symantec
http://www.symantec.com/security_response/vulnerability.jsp?bid=27641
|
|
Last Updated ( Saturday, 11 December 2010 )
|