Gentoo Archives: gentoo-announce

From: Matthias Geerdsen <vorlon@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200507-09 ] Adobe Acrobat Reader: Buffer overflow vulnerability
Date: Mon, 11 Jul 2005 13:44:06
Message-Id: 20050711132343.GA12097@kosh.atw.wh.local
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200507-09
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Adobe Acrobat Reader: Buffer overflow vulnerability
9 Date: July 11, 2005
10 Bugs: #98101
11 ID: 200507-09
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Adobe Acrobat Reader is vulnerable to a buffer overflow that could lead
19 to remote execution of arbitrary code.
20
21 Background
22 ==========
23
24 Adobe Acrobat Reader is a utility used to view PDF files.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 app-text/acroread <= 5.10 >= 7.0
33
34 Description
35 ===========
36
37 A buffer overflow has been discovered in the UnixAppOpenFilePerform()
38 function, which is called when Adobe Acrobat Reader tries to open a
39 file with the "\Filespec" tag.
40
41 Impact
42 ======
43
44 By enticing a user to open a specially crafted PDF document, a remote
45 attacker could exploit this vulnerability to execute arbitrary code.
46
47 Workaround
48 ==========
49
50 There is no known workaround at this time.
51
52 Resolution
53 ==========
54
55 Since Adobe will most likely not update the 5.0 series of Adobe Acrobat
56 Reader for Linux, all users should upgrade to the latest available
57 version of the 7.0 series:
58
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=app-text/acroread-7.0"
61
62 References
63 ==========
64
65 [ 1 ] CAN-2005-1625
66 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1625
67 [ 2 ] iDEFENSE Security Advisory
68 http://www.idefense.com/application/poi/display?id=279&type=vulnerabilities&flashstatus=true
69 [ 3 ] Adobe Security Advisory
70 http://www.adobe.com/support/techdocs/329083.html
71
72 Availability
73 ============
74
75 This GLSA and any updates to it are available for viewing at
76 the Gentoo Security Website:
77
78 http://security.gentoo.org/glsa/glsa-200507-09.xml
79
80 Concerns?
81 =========
82
83 Security is a primary focus of Gentoo Linux and ensuring the
84 confidentiality and security of our users machines is of utmost
85 importance to us. Any security concerns should be addressed to
86 security@g.o or alternatively, you may file a bug at
87 http://bugs.gentoo.org.
88
89 License
90 =======
91
92 Copyright 2005 Gentoo Foundation, Inc; referenced text
93 belongs to its owner(s).
94
95 The contents of this document are licensed under the
96 Creative Commons - Attribution / Share Alike license.
97
98 http://creativecommons.org/licenses/by-sa/2.0