SuSE: 2007-011: Acrobat Reader 7.0.9 Security Update
Summary
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
______________________________________________________________________________
SUSE Security Announcement
Package: acroread
Announcement ID: SUSE-SA:2007:011
Date: Mon, 22 Jan 2007 18:00:00 +0000
Affected Products: SUSE LINUX 9.3
SUSE LINUX 10.0
SUSE LINUX 10.1
openSUSE 10.2
Novell Linux Desktop 9
SUSE SLED 10
Vulnerability Type: remote code execution
Severity (1-10): 8
SUSE Default Package: yes
Cross-References: CVE-2006-5857, CVE-2007-0044, CVE-2007-0045
CVE-2007-0046, CVE-2007-0047, CVE-2007-0048
Content of This Advisory:
1) Security Vulnerability Resolved:
acroread 7.0.9 security update
Problem Description
2) Solution or Work-Around
3) Special Instructions and Notes
4) Package Location and Checksums
5) Pending Vulnerabilities, Solutions, and Work-Arounds:
See SUSE Security Summary Report.
6) Authenticity Verification and Additional Information
______________________________________________________________________________
1) Problem Description and Brief Discussion
The Adobe Acrobat Reader has been updated to version 7.0.9.
This update also includes following security fixes:
CVE-2006-5857: A memory corruption problem was fixed in Adobe Acrobat
Reader can potentially lead to code execution.
CVE-2007-0044: Universal Cross Site Request Forgery (CSRF) problems
were fixed in the Acrobat Reader plugin which could be
exploited by remote attackers to conduct CSRF attacks
using any site that is providing PDFs.
CVE-2007-0045: Cross site scripting problems in the Acrobat Reader
plugin were fixed, which could be exploited by remote
attackers to conduct XSS attacks against any site that
is providing PDFs.
CVE-2007-0046: A double free problem in the Acrobat Reader plugin was fixed
which could be used by remote attackers to potentially execute
arbitrary code.
Note that all platforms using Adobe Reader currently have
counter measures against such attack where it will just
cause a controlled abort().
CVE-2007-0047 and CVE-2007-0048 affect only Microsoft Windows and
Internet Explorer.
Please note that the Acrobat Reader on SUSE Linux Enterprise Server
9 is affected too, but can not be updated currently due to GTK+
2.4 requirements. We are trying to find a solution.
Acrobat Reader on SUSE Linux Enterprise Server 8 and SUSE Linux
Desktop 1 is no longer supported and should be deinstalled.
2) Solution or Work-Around
As a workaround, you can use the free PDF readers, kpdf, xpdf, evince,
and others.
Please install the updated packages.
3) Special Instructions and Notes
Please close and restart all running instances of acroread after
the update.
4) Package Location and Checksums
The preferred method for installing security updates is to use the YaST
Online Update (YOU) tool. YOU detects which updates are required and
automatically performs the necessary steps to verify and install them.
Alternatively, download the update packages for your distribution manually
and verify their integrity by the methods listed in Section 6 of this
announcement. Then install the packages using the command
rpm -Fhv
References