Red Hat: acrobat security issues
Summary
Summary
The Adobe Acrobat Reader browser allows for the viewing, distributing, andprinting of documents in portable document format (PDF).iDEFENSE has reported that Adobe Acrobat Reader 5.0 contains a bufferoverflow when decoding uuencoded documents. An attacker could executearbitrary code on a victim's machine if a user opens a specially crafteduuencoded document. This issue poses the threat of remote execution, sinceAcrobat Reader may be the default handler for PDF files. The CommonVulnerabilities and Exposures project has assigned the name CAN-2004-0631to this issue.iDEFENSE also reported that Adobe Acrobat Reader 5.0 contains an inputvalidation error in its uuencoding feature. An attacker could create afile with a specially crafted file name which could lead to arbitrarycommand execution on a victim's machine. The Common Vulnerabilities andExposures project has assigned the name CAN-2004-0630 to this issue.All users of Acrobat Reader are advised to upgrade to this updated package,which is not vulnerable to these issues.
Solution
Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:
up2date
For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:
http://www.redhat.com/docs/manuals/enterprise/
5. RPMs required:
Red Hat Enterprise Linux LACD 3AS:
i386:
ab70943b0e7d266df504c7b66b5e5c26 acroread-5.09-1.i386.rpm
a2bfb5fde963cc51804a18ea659a16e5 acroread-plugin-5.09-1.i386.rpm
Red Hat Enterprise Linux LACD 3Desktop:
i386:
ab70943b0e7d266df504c7b66b5e5c26 acroread-5.09-1.i386.rpm
a2bfb5fde963cc51804a18ea659a16e5 acroread-plugin-5.09-1.i386.rpm
Red Hat Enterprise Linux LACD 3ES:
i386:
ab70943b0e7d266df504c7b66b5e5c26 acroread-5.09-1.i386.rpm
a2bfb5fde963cc51804a18ea659a16e5 acroread-plugin-5.09-1.i386.rpm
Red Hat Enterprise Linux LACD 3WS:
i386:
ab70943b0e7d266df504c7b66b5e5c26 acroread-5.09-1.i386.rpm
a2bfb5fde963cc51804a18ea659a16e5 acroread-plugin-5.09-1.i386.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
References
Package List
Topic
An updated Adobe Acrobat Reader package that fixes multiple security issuesis now available.
Topic
Relevant Releases Architectures
Red Hat Enterprise Linux LACD 3AS - i386
Red Hat Enterprise Linux LACD 3Desktop - i386
Red Hat Enterprise Linux LACD 3ES - i386
Red Hat Enterprise Linux LACD 3WS - i386
Bugs Fixed