adobe reader 8.1.4 / 9.1 getannots() remote code execution
Posted: Sat May 09, 2009 5:56 am
Versions 8.1.4 and 9.1 of Adobe Reader for linux are vulnerable to remote code execution. the following link jumps to a brief overview of the situation.
[url=\"http://www.securityfocus.com/bid/34736/discuss\"]http://www.securityfocus.com/bid/34736/discuss[/url]
currently there are no patches supplied as the vendor is investigating this issue, I have confirmed it to be valid however. If you are running this version of adobe on a linux box my suggestion is if you dont trust the site you are getting a PDF from, be sure to either turn off the browser plugin for pdf's so it will not automatically run them, and be sure to first download the pdf to your hdd. From there check the notes in the PDF to be certain they are not host to the exploit code. For those who do not know, remote code execution is a serious problem. Basically whatever you could do sitting at your computer, a remote attacker could also perform on your machine, and i dont mean just solitaire. You can spawn shells, format discs, you name it.
I will keep an eye out for a vendor supplied patch or similar update to post here.
Be Safe.
[url=\"http://www.securityfocus.com/bid/34736/discuss\"]http://www.securityfocus.com/bid/34736/discuss[/url]
currently there are no patches supplied as the vendor is investigating this issue, I have confirmed it to be valid however. If you are running this version of adobe on a linux box my suggestion is if you dont trust the site you are getting a PDF from, be sure to either turn off the browser plugin for pdf's so it will not automatically run them, and be sure to first download the pdf to your hdd. From there check the notes in the PDF to be certain they are not host to the exploit code. For those who do not know, remote code execution is a serious problem. Basically whatever you could do sitting at your computer, a remote attacker could also perform on your machine, and i dont mean just solitaire. You can spawn shells, format discs, you name it.
I will keep an eye out for a vendor supplied patch or similar update to post here.
Be Safe.