(Sun Issues Advisory) Adobe Acrobat Temporary File Race Condition in 'acroread' Wrapper Script Lets Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1020617 |
|
SecurityTracker URL: http://securitytracker.com/id/1020617
|
|
CVE Reference:
CVE-2008-0883
(Links to External Site)
|
Date: Aug 4 2008
|
Impact:
Execution of arbitrary code via local system, Modification of system information, Modification of user information, User access via local system
|
Vendor Confirmed: Yes
|
Version(s): 8.1.2
|
Description:
A vulnerability was reported in Adobe Acrobat Reader for Linux. A local user can obtain elevated privileges on the target system.
The "acroread" wrapper script uses unsafe temporary files (in '/tmp') when processing SSL certificates. A local user can gain elevated privileges.
SUSE reported this vulnerability.
|
Impact:
A local user can modify files on the target system to gain elevated privileges on the target system.
|
Solution:
Sun is working on a fix.
The Sun advisory is available at:
http://sunsolve.sun.com/search/document.do?assetkey=1-66-240106-1
|
Vendor URL: www.adobe.com/support/security/advisories/apsa08-02.html (Links to External Site)
|
Cause:
Access control error, State error
|
Underlying OS:
UNIX (Solaris - SunOS)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Sun, 3 Aug 2008 22:11:20 -0400
Subject: http://sunsolve.sun.com/search/document.do?assetkey=1-66-240106-1
|
CVE-2008-0883
CVE-2008-2641
|
|