SUSE Security Update: Security update for Acrobat Reader
______________________________________________________________________________

Announcement ID:    SUSE-SU-2012:0524-1
Rating:             important
References:         #756574 
Cross-References:   CVE-2012-0774 CVE-2012-0775 CVE-2012-0777
                   
Affected Products:
                    SUSE Linux Enterprise Desktop 10 SP4
______________________________________________________________________________

   An update that fixes three vulnerabilities is now
   available. It includes two new package versions.

Description:


   The Acrobat Reader has been updated to version 9.5.1 to fix
   the following  issues:

   * CVE-2012-0774: crafted fonts inside PDFs could allow
   attackers to cause an integer overflow, resulting in the
   possibility of arbitrary code execution
   * CVE-2012-0775, CVE-2012-0777: an issue in acroread's
   javascript API could allowattackers to cause a denial of
   service or potentially execute arbitrary code

   Security Issue references:

   * CVE-2012-0774
   
   * CVE-2012-0775
   
   * CVE-2012-0777
   



Package List:

   - SUSE Linux Enterprise Desktop 10 SP4 (noarch) [New Version: 9.4.6]:

      acroread-cmaps-9.4.6-0.6.1
      acroread-fonts-ja-9.4.6-0.6.1
      acroread-fonts-ko-9.4.6-0.6.1
      acroread-fonts-zh_CN-9.4.6-0.6.1
      acroread-fonts-zh_TW-9.4.6-0.6.1

   - SUSE Linux Enterprise Desktop 10 SP4 (i586) [New Version: 9.5.1]:

      acroread-9.5.1-0.6.1


References:

   https://www.suse.com/security/cve/CVE-2012-0774.html
   https://www.suse.com/security/cve/CVE-2012-0775.html
   https://www.suse.com/security/cve/CVE-2012-0777.html
   https://bugzilla.novell.com/756574
   https://login.microfocus.com/nidp/app/login

SuSE: 2012:0524-1: important: Acrobat Reader

April 18, 2012
An update that fixes three vulnerabilities is now An update that fixes three vulnerabilities is now An update that fixes three vulnerabilities is now available

Summary

The Acrobat Reader has been updated to version 9.5.1 to fix the following issues: * CVE-2012-0774: crafted fonts inside PDFs could allow attackers to cause an integer overflow, resulting in the possibility of arbitrary code execution * CVE-2012-0775, CVE-2012-0777: an issue in acroread's javascript API could allowattackers to cause a denial of service or potentially execute arbitrary code Security Issue references: * CVE-2012-0774 * CVE-2012-0775 * CVE-2012-0777 Package List: - SUSE Linux Enterprise Desktop 10 SP4 (noarch) [New Version: 9.4.6]: acroread-cmaps-9.4.6-0.6.1 acroread-fonts-ja-9.4.6-0.6.1 acroread-fonts-ko-9.4.6-0.6.1 acroread-fonts-zh_CN-9.4.6-0.6.1 acroread-fonts-zh_TW-9.4.6-0.6.1 - SUSE Linux Enterprise Desktop 10 SP4 (i586) [New Version: 9.5.1]: acroread-9.5.1-0.6.1

References

#756574

Cross- CVE-2012-0774 CVE-2012-0775 CVE-2012-0777

Affected Products:

SUSE Linux Enterprise Desktop 10 SP4

https://www.suse.com/security/cve/CVE-2012-0774.html

https://www.suse.com/security/cve/CVE-2012-0775.html

https://www.suse.com/security/cve/CVE-2012-0777.html

https://bugzilla.novell.com/756574

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2012:0524-1
Rating: important

Related News