|Category:||Red Hat Local Security Checks|
|Title:||RedHat Security Advisory RHSA-2008:0641|
The remote host is missing updates announced in
Adobe Acrobat Reader allows users to view and print documents in Portable
Document Format (PDF).
Acrobat Reader. A malicious PDF file could cause Acrobat Reader to crash
or, potentially, execute arbitrary code as the user running Acrobat Reader.
An insecure temporary file usage issue was discovered in the Acrobat Reader
acroread startup script. A local attacker could potentially overwrite
arbitrary files that were writable by the user running Acrobat Reader, if
the victim ran acroread with certain command line arguments.
All acroread users are advised to upgrade to these updated packages, that
contain Acrobat Reader version 8.1.2 Security Update 1, and are not
vulnerable to these issues.
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date
Risk factor : Critical
Common Vulnerability Exposure (CVE) ID: CVE-2008-0883|
BugTraq ID: 28091
SuSE Security Announcement: SUSE-SR:2008:005 (Google Search)
XForce ISS Database: adobe-reader-acroread-symlink(40987)
Common Vulnerability Exposure (CVE) ID: CVE-2008-2641
BugTraq ID: 29908
CERT/CC vulnerability note: VU#788019
SuSE Security Announcement: SUSE-SR:2008:016 (Google Search)
|Copyright||Copyright (c) 2008 E-Soft Inc. http://www.securityspace.com|
|This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.