Adobe Reader: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200910-03 / acroread |
| Release Date |
October 25, 2009 |
| Latest Revision |
October 25, 2009: 01 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| app-text/acroread |
<
9.2 |
>=
9.2 |
All supported architectures
|
Related bugreports:
#289016
Synopsis
Multiple vulnerabilities in Adobe Reader might result in the execution of
arbitrary code, or other attacks.
2.
Impact Information
Background
Adobe Reader (formerly Adobe Acrobat Reader) is a closed-source PDF
reader.
Description
Multiple vulnerabilities were discovered in Adobe Reader. For further
information please consult the CVE entries and the Adobe Security
Bulletin referenced below.
Impact
A remote attacker might entice a user to open a specially crafted PDF
file, possibly resulting in the execution of arbitrary code with the
privileges of the user running the application, Denial of Service, the
creation of arbitrary files on the victim's system, "Trust Manager"
bypass, or social engineering attacks.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Adobe Reader users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-text/acroread-9.2"
|
4.
References
|