Adobe Acrobat Buffer Overflow in 'AcroPDF.dll' ActiveX May Let Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1017297
|
|
SecurityTracker URL: http://securitytracker.com/id?1017297
|
|
CVE Reference: CVE-2006-6027
(Links to External Site)
|
Updated: Dec 6 2006
|
Original Entry Date: Nov 29 2006
|
Impact: Denial of service via network, Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Advisory: Adobe Advisory
|
Version(s): 7.0.0 - 7.0.8
|
Description: A vulnerability was reported in Adobe Acrobat and Adobe Reader. A remote user can cause denial of service conditions. A remote user may be able to cause arbitrary code to be executed on the target user's system.
A remote user can create specially crafted HTML that, when loaded by the target user, will trigger a flaw in the 'AcroPDF.dll' ActiveX
component. This can cause the target user's browser to crash. It may be possible to execute arbitrary code on the target user's
system with the privileges of the target user. However, code execution was not confirmed.
A demonstration exploit is available
at:
http://downloads.securityfocus.com/vulnerabilities/exploits/21155-AcroPDF_DoS.html
|
Impact: A remote user can create HTML that, when loaded by the target user, will cause the target user's Internet Explorer browser to crash or potentially execute arbitrary code.
|
Solution: The vendor has issued a fixed version (Adobe Reader 8), available at:
http://www.adobe.com/products/acrobat/readstep2.html
Adobe
Acrobat users can follow directions in the vendor's advisory to correct the vulnerability.
The original Adobe advisory is available
at:
www.adobe.com/support/security/bulletins/apsb06-20.html
The original Adobe advisory is available at:
http://www.adobe.com/support/security/advisories/apsa06-
02.html
|
Vendor URL: www.adobe.com/support/security/bulletins/apsb06-20.html (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 28 Nov 2006 20:33:39 -0500
Subject: Potential vulnerabilities in Adobe Reader and Acrobat
|
http://www.adobe.com/support/security/advisories/apsa06-02.html
CVE-2006-6027
|
|