Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 374637 - <app-text/acroread-9.4.5: Multiple vulnerabilities (CVE-2011-{2094,2095,2096,2097,2098,2099,2100,2101,2102,2103,2104,2105,2106})
Summary: <app-text/acroread-9.4.5: Multiple vulnerabilities (CVE-2011-{2094,2095,2096,...
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-07-10 01:39 UTC by GLSAMaker/CVETool Bot
Modified: 2011-07-11 08:21 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2011-07-10 01:39:39 UTC
CVE-2011-2106 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2106):
  Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before
  10.1 on Mac OS X allow attackers to execute arbitrary code or cause a denial
  of service (memory corruption) via unspecified vectors.

CVE-2011-2105 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2105):
  Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before
  10.1 on Windows and Mac OS X allow attackers to cause a denial of service
  (memory corruption) or possibly have unspecified other impact via unknown
  vectors.

CVE-2011-2104 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2104):
  Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before
  10.1 on Windows and Mac OS X allow attackers to cause a denial of service
  (memory corruption) via unspecified vectors.

CVE-2011-2103 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2103):
  Adobe Reader and Acrobat 8.x before 8.3 on Windows and Mac OS X allow
  attackers to execute arbitrary code or cause a denial of service (memory
  corruption) via unspecified vectors.

CVE-2011-2102 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2102):
  Unspecified vulnerability in Adobe Reader and Acrobat before 10.1 on Windows
  and Mac OS X allows attackers to bypass intended access restrictions via
  unknown vectors.

CVE-2011-2101 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2101):
  Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before
  10.1 on Windows and Mac OS X do not properly restrict script, which allows
  attackers to execute arbitrary code via a crafted document, related to a
  "cross document script execution vulnerability."

CVE-2011-2100 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2100):
  Untrusted search path vulnerability in Adobe Reader and Acrobat 8.x before
  8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows allows local users to
  gain privileges via a Trojan horse DLL in the current working directory.

CVE-2011-2099 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2099):
  Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before
  10.1 on Windows and Mac OS X allow attackers to execute arbitrary code or
  cause a denial of service (memory corruption) via unspecified vectors, a
  different vulnerability than CVE-2011-2098.

CVE-2011-2098 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2098):
  Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before
  10.1 on Windows and Mac OS X allow attackers to execute arbitrary code or
  cause a denial of service (memory corruption) via unspecified vectors, a
  different vulnerability than CVE-2011-2099.

CVE-2011-2097 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2097):
  Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before
  9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers to
  execute arbitrary code via unspecified vectors, a different vulnerability
  than CVE-2011-2094 and CVE-2011-2095.

CVE-2011-2096 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2096):
  Heap-based buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x
  before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers
  to execute arbitrary code via unspecified vectors.

CVE-2011-2095 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2095):
  Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before
  9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers to
  execute arbitrary code via unspecified vectors, a different vulnerability
  than CVE-2011-2094 and CVE-2011-2097.

CVE-2011-2094 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2094):
  Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before
  9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers to
  execute arbitrary code via unspecified vectors, a different vulnerability
  than CVE-2011-2095 and CVE-2011-2097.
Comment 1 Tim Sammut (RETIRED) gentoo-dev 2011-07-11 02:00:23 UTC
I do not believe these vulnerabilities affect Reader on Linux. 9.4.2 is the most recent Linux version available upstream.
Comment 2 Tomas Hoger 2011-07-11 08:21:30 UTC
Some of them probably do, but they still won't be fixed before September:

http://blogs.adobe.com/asset/2011/06/notes-on-adobe-reader-and-acrobat-10-1.html
search for "Support Model Change for Adobe Reader for Linux"