Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 245599 (CVE-2008-2992) - app-text/acroread<=8.1.2 Javascript Printf Buffer Overflow (CVE-2008-2992)
Summary: app-text/acroread<=8.1.2 Javascript Printf Buffer Overflow (CVE-2008-2992)
Status: RESOLVED DUPLICATE of bug 225483
Alias: CVE-2008-2992
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.coresecurity.com/content/a...
Whiteboard: A2 [ebuild|upstream]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-11-04 22:57 UTC by Stefan Behte (RETIRED)
Modified: 2008-11-04 23:08 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2008-11-04 22:57:29 UTC
Adobe Reader is arguably the world's most ubiquitous electronic document sharing application. The software can be used to view, search, digitally sign, verify, print, and collaborate on Adobe PDF files, and includes scripting functionality to allow for extended customization and extensibility.

Adobe Reader suffers from a stack buffer overflow when parsing specially crafted (invalid) PDF files. The vulnerability is caused due to a boundary error when parsing format strings containing a floating point specifier in the "util.printf()" JavaScript function. Successful exploitation of the vulnerability requires that users open a maliciously crafted PDF file thereby allowing attackers to gain access to vulnerable systems and assume the privileges of a user running Acrobat Reader. Adobe Reader version 9, which was released in June 2008, is not vulnerable to the reported problem. 

Workaround:
Alternatively, a possible workaround for this vulnerability is to disable JavaScript in Adobe Reader and Acrobat (in the software's Edit/Preferences menu). Disabling JavaScript will prevent the issue, although it will also prevent many basic Acrobat and Reader workflows from properly functioning.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-04 22:59:46 UTC
Version 9 is not affected, can we get it into the tree?
Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-04 23:08:35 UTC
Sorry, for the bugspam, same as
http://www.adobe.com/support/security/bulletins/apsb08-19.html


*** This bug has been marked as a duplicate of bug 225483 ***