Infesting you with Virus News
 

Vulnerabilities

Adobe Reader and Acrobat util.printf() JavaScript function remote stack... (PC1-2008-0818)

Overview

Vulnerability chart

Adobe Reader and Acrobat include a stack buffer overflow vulnerability in the util.printf() JavaScript function. By using it unauthenticated attacker may be enabled to execute arbitrary code on a vulnerable system.
Remote Access
Unknown patch
availability
Patch implementation
unknown

References to Advisories, Solutions, and Tools

Description:

Adobe Reader is software created to view Portable Document Format (PDF) files. Adobe Acrobat is software that is able to create PDF files. Adobe Reader and Acrobat support JavaScript in PDF documents. According to the Acrobat Forms JavaScript Object Specification, the util.printf() function "... will format one or more values as a string according to a format string. This is similar to the C function of the same name
Adobe Reader and Acrobat fail to sufficiently validate input to the util.printf() JavaScript function. It can lead to a stack buffer overflow vulnerability. Exploit code for this vulnerability is publicly available.

Impact:

If a user is persuaded to open a specially-crafted PDF file, a remote, unauthenticated attacker might be able to execute arbitrary code. This can be done in several ways, for example, opening an email attachment or viewing a web page.

Solution:

Users are recommended to check for new versions and patches of the software program and upgrade their systems.

References:http://www.adobe.com/support/security/bulletins/apsb08-19.html
http://secunia.com/advisories/29773/
http://secunia.com/advisories/29941/
http://www.securityfocus.com/bid/30035
http://www.coresecurity.com/content/adobe-reader-buffer-overflow

Say something interesting!

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Latest Comments

July 31, 2010
http://farmclas .. m-chambers.htmlkim chambers, 132592, http://westland .. -templates.htmlcv templates,... more..
July 31, 2010
http://temple-b .. 6/fha-203k.htmlfha 203k, :(, http://uksoccer .. sy-grammar.htmleasy grammar, hbt,... more..
July 31, 2010
http://thedukes .. ncy-meyers.htmlnancy meyers, 8332, http://maillots .. /***-girl.html*** girl,... more..
more comments..
rss
Home > Vulnerabilities > PC1-2008-0818