Sponsored Community Message Browse Free. Go deeper with Full Access. Free visitors can browse public knowledge. Full Access unlocks participation, member areas, and an ad-free experience.

PDF Cautionary Note-gctid32092

Started by KhepraEvolutionary, Dec 02, 2008, 06:20 PM

Previous topic - Next topic
Ee ee m htp
Greetings.
 
Be cautious opening documents from people you do not know. Also make sure the people you do know are using updated and valid malware protection because they can unintentionally cause you problems.
This could be a way to get more money from US so you decide how to or how not to address this.
 
She ee m htp.
 
Khepra

Vulnerability Note VU#593409
 
Adobe Reader and Acrobat util.printf() JavaScript function stack buffer overflow
 
Overview
 
Adobe Reader and Acrobat contain a stack buffer overflow in the util.printf() JavaScript function, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system. I. Description
 
Adobe Reader is software designed to view Portable Document Format (PDF) files. Adobe Acrobat is software that can create PDF files. Adobe Reader and Acrobat support JavaScript in PDF documents. According to the Acrobat Forms JavaScript Object Specification, the util.printf() function "... will format one or more values as a string according to a format string. This is similar to the C function of the same name."
Adobe Reader and Acrobat fail to sufficiently validate input to the util.printf() JavaScript function, which can result in a stack buffer overflow. Exploit code for this vulnerability is publicly available. II. Impact
 
By convincing a user to open a specially-crafted PDF file, a remote, unauthenticated attacker may be able to execute arbitrary code. This can happen in several ways, such as opening an email attachment or viewing a web page. III. Solution
 
Apply an update
This issue is addressed in Adobe Reader and Adobe Acrobat 8.1.3. More details are available in Adobe Security Bulletin APSB08-019. Please also consider the following workarounds to help mitigate this and other vulnerabilities in Adobe Reader:
 
Disable the displaying of PDF documents in the web browser
 
Preventing PDF documents from opening inside a web browser may mitigate this vulnerability. If this workaround is applied to updated versions of the Adobe reader, it may mitigate future vulnerabilities.

To prevent PDF documents from automatically being opened in a web browser:'"
Yao Khepra The Evolutionary


Evolution through Fusion Founder/National Vice Chair


New York Facilitator SRDC/PADU (6th Region Diaspora Caucus/Pan Kmtyw Diaspora Union)


http://srdcinternational.org">http://srdcinternational.org


http://padu-srdc.ning.com">http://padu-srdc.ning.com


Proud and Humble Servant operating with Sincerity Integrity and Transparency


Evolution Through Fusion is the only solution to provide a P.A.S.S. (Prepared Autonomous Sustainable Solution) through the 21st Century and beyond.