<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>170177</bug_id>
          <alias>CVE-2007-1199</alias>
          <creation_ts>2007-03-09 21:00 0000</creation_ts>
          <short_desc>app-text/acroread &lt; 8.1.2 Multiple vulnerabilities (CVE-2007-{1199,5659,5663,5666},CVE-2008-{0726,0655,0667})</short_desc>
          <delta_ts>2008-03-03 00:11:17 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/24408/</bug_file_loc>
          <status_whiteboard>B2 [glsa] Falco</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>falco@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>kevquinn@gentoo.org</cc>
    
    <cc>printing@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-03-09 21:00:52 0000</bug_when>
            <thetext>Hello,

That&apos;s a weak vulnerability but that&apos;s a security issue.

quoting Secunia:
&quot;The problem is that it is possible to launch &quot;file://&quot; URLs from within PDF files. This can be exploited to e.g. read arbitrary files on the system and send them to the attacker.&quot;

Credits: pdp

There is no known fixed version yet</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kevquinn@gentoo.org</who>
            <bug_when>2007-03-27 12:56:05 0000</bug_when>
            <thetext>Since this is a binary-only package, there&apos;s nothing we can do until Adobe release a new version.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-08-24 11:54:31 0000</bug_when>
            <thetext>upstream takes way too long... printing/security, since we can&apos;t fix this and we can&apos;t let a vulnerable package in the tree, what do you think of pmasking, at least until this is fixed, or even for removal? please comment.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-09-14 10:26:28 0000</bug_when>
            <thetext>acroread 8.1.1 for linux is out. I don&apos;t know if it fixes this.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kevquinn@gentoo.org</who>
            <bug_when>2007-09-27 22:26:01 0000</bug_when>
            <thetext>8.1.1 issues a pop-up warning box using the PoCs I could find, asking the user to confirm the access request - so I guess that sorts ths issue out.

However 8.1.1 is only available in English; I&apos;m reluctant to remove the old version until Adobe have released all the language variants (doesn&apos;t usually take them too long, once they&apos;ve released the US English version).  I don&apos;t think the issue is critical enough to remove stuff before replacements are available.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-10-17 18:37:24 0000</bug_when>
            <thetext>Any news on this one?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kevquinn@gentoo.org</who>
            <bug_when>2007-10-21 15:47:15 0000</bug_when>
            <thetext>Sorry, none yet.  Still waiting for Adobe to release it in other languages.

I presume they&apos;ve gotten delayed, having to deal with http://www.adobe.com/support/security/advisories/apsa07-04.html
which looks like a Windows-only issue, to do with the way mailto: URIs are handled by IE 7.  A PoC available here: 

http://security.fedora-hosting.com/0day/pdf/pdf_poc.txt

discussion here:

http://www.gnucitizen.org/blog/0day-pdf-pwns-windows

It does trigger Firefox on Gentoo, although it doesn&apos;t achieve anything here (not least because my FireFox isn&apos;t configured to handle mailto: URLs).
Either way it doesn&apos;t change the situation for us - we&apos;re still waiting for the translated 8.1.1 to appear (perhaps it&apos;ll be an 8.1.2 when the new issue is dealt with).
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>martin@pcalpha.com</who>
            <bug_when>2007-12-12 07:32:09 0000</bug_when>
            <thetext>Seems like the multilingual versions of the next acroread are out so this package could be updated.

http://ardownload.adobe.com/pub/adobe/reader/unix/8.x/8.1.1/enu/AdobeReader_enu-8.1.1-1.i486.tar.gz
http://ardownload.adobe.com/pub/adobe/reader/unix/8.x/8.1.1/fra/AdobeReader_fra-8.1.1-1.i486.tar.gz
http://ardownload.adobe.com/pub/adobe/reader/unix/8.x/8.1.1/deu/AdobeReader_deu-8.1.1-1.i486.tar.gz
http://ardownload.adobe.com/pub/adobe/reader/unix/8.x/8.1.1/esp/AdobeReader_esp-8.1.1-1.i486.tar.gz
[...]
http://www.adobe.com/products/acrobat/readstep2_allversions.html</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-12-14 15:32:51 0000</bug_when>
            <thetext>(In reply to comment #7)
&gt; Seems like the multilingual versions of the next acroread are out so this
&gt; package could be updated.
&gt; 
&gt; http://ardownload.adobe.com/pub/adobe/reader/unix/8.x/8.1.1/enu/AdobeReader_enu-8.1.1-1.i486.tar.gz
&gt; http://ardownload.adobe.com/pub/adobe/reader/unix/8.x/8.1.1/fra/AdobeReader_fra-8.1.1-1.i486.tar.gz
&gt; http://ardownload.adobe.com/pub/adobe/reader/unix/8.x/8.1.1/deu/AdobeReader_deu-8.1.1-1.i486.tar.gz
&gt; http://ardownload.adobe.com/pub/adobe/reader/unix/8.x/8.1.1/esp/AdobeReader_esp-8.1.1-1.i486.tar.gz
&gt; [...]
&gt; http://www.adobe.com/products/acrobat/readstep2_allversions.html
&gt; 

Thanks for the notification. printing, please provide updated ebuilds.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-01-08 01:17:51 0000</bug_when>
            <thetext>printing, please bump.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-01-30 10:53:58 0000</bug_when>
            <thetext>(In reply to comment #9)
&gt; printing, please bump.
&gt; 

*ping*</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tgurr@gentoo.org</who>
            <bug_when>2008-01-30 20:52:44 0000</bug_when>
            <thetext>Sorry for the huge delay, an updated version of the ebuild is in CVS now:
acroread-8.1.1-r2.ebuild

It should also work on 64bit, by depending on seamonkey-bin to provide a working gtkembedmoz.so. That is not optimal but currently there&apos;s no other way since firefox-bin doesn&apos;t ship with a gtkembedmoz.so anymore. Though the mozilla herd is so kind and considers putting a xulrunner-bin into the tree for us.

Language support is again as complete as it was in acroread7.

The only known remaining problem so far are a few
scanelf: rpath_security_checks(): Security problem with relative DT_RPATH &apos;.&apos;
warnings while emerging the ebuild. If that doesn&apos;t hurt, I&apos;d like to unmask acroread asap to get some further testing and finally getting it stable if no serious problems arise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tgurr@gentoo.org</who>
            <bug_when>2008-02-07 21:53:14 0000</bug_when>
            <thetext>acroread-8.1.2 is in the tree and unmasked now, should be fine to go stable in a few days.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2008-02-09 15:58:18 0000</bug_when>
            <thetext>...] the update includes several important security fixes, among them a few of critical severity that could be remotely exploitable. [...

http://www.adobe.com/support/security/advisories/apsa08-01.html


I&apos;d say 8.1.2 should go stable asap.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2008-02-10 14:38:00 0000</bug_when>
            <thetext>amd64 and x86 please test and mark stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tester@gentoo.org</who>
            <bug_when>2008-02-10 22:30:34 0000</bug_when>
            <thetext>amd64 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-02-10 22:37:42 0000</bug_when>
            <thetext>...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>cla@gentoo.org</who>
            <bug_when>2008-02-10 23:06:29 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2008-02-11 20:49:13 0000</bug_when>
            <thetext>This one is ready for GLSA vote. I vote YES.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-02-12 00:02:31 0000</bug_when>
            <thetext>Rerating B2, filed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-02-12 17:49:25 0000</bug_when>
            <thetext>See also http://secunia.com/advisories/28802

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lars@chaotika.org</who>
            <bug_when>2008-02-16 15:55:43 0000</bug_when>
            <thetext>please add CVE-2008-0726 - i could not add it cause i dont have the propper permissions</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-02-23 18:43:45 0000</bug_when>
            <thetext>Fixed in release snapshot.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-03 00:11:17 0000</bug_when>
            <thetext>GLSA 200803-01</thetext>
          </long_desc>
      
    </bug>

</bugzilla>