Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51049
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2004:432
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory RHSA-2004:432.

The Adobe Acrobat Reader browser allows for the viewing, distributing, and
printing of documents in portable document format (PDF).

iDEFENSE has reported that Adobe Acrobat Reader 5.0 contains a buffer
overflow when decoding uuencoded documents. An attacker could execute
arbitrary code on a victim's machine if a user opens a specially crafted
uuencoded document. This issue poses the threat of remote execution, since
Acrobat Reader may be the default handler for PDF files. The Common
Vulnerabilities and Exposures project has assigned the name CVE-2004-0631
to this issue.

iDEFENSE also reported that Adobe Acrobat Reader 5.0 contains an input
validation error in its uuencoding feature. An attacker could create a
file with a specially crafted file name which could lead to arbitrary
command execution on a victim's machine. The Common Vulnerabilities and
Exposures project has assigned the name CVE-2004-0630 to this issue.

All users of Acrobat Reader are advised to upgrade to this updated package,
which is not vulnerable to these issues.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2004-432.html
http://www.idefense.com/application/poi/display?id=125&type=vulnerabilities
http://www.idefense.com/application/poi/display?id=124&type=vulnerabilities

Risk factor : Critical

CVSS Score:
10.0

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-0631
BugTraq ID: 10932
http://www.securityfocus.com/bid/10932
http://security.gentoo.org/glsa/glsa-200408-14.xml
http://www.idefense.com/application/poi/display?id=125&type=vulnerabilities
http://www.redhat.com/support/errata/RHSA-2004-432.html
XForce ISS Database: adobe-acrobat-uudecode-bo(16972)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16972
Common Vulnerability Exposure (CVE) ID: CVE-2004-0630
BugTraq ID: 10931
http://www.securityfocus.com/bid/10931
http://www.idefense.com/application/poi/display?id=124&type=vulnerabilities
XForce ISS Database: acrobat-reader-execute-code(16973)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16973
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.