[NT] Adobe Acrobat/Reader Information Disclosure (XML External Entity)

From: SecuriTeam (support_at_securiteam.com)
Date: 06/20/05

  • Next message: SecuriTeam: "[EXPL] IBM AIX Netpmon Privileges Escalation Vulnerability Exploit"
    To: list@securiteam.com
    Date: 20 Jun 2005 10:08:10 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Adobe Acrobat/Reader Information Disclosure (XML External Entity)
    ------------------------------------------------------------------------

    SUMMARY

    " <http://www.adobe.com/products/acrobatstd/main.html> Acrobat is the
    Adobe family of PDF (Portable Document Format) file editors and viewers(
    <http://en.wikipedia.org/wiki/Adobe_Reader> wiki)."

    Exploiting flaws in XML parsing of Adobe Acrobat and Adobe Reader allows
    remote attacker to discover the existence of local files on a vulnerable
    system.

    DETAILS

    Vulnerable Systems:
     * Adobe Reader 7.0, 7.0.1.
     * Adobe Acrobat 7.0, 7.0.1

    Immune Systems:
     * Adobe Reader 7.0.2 ( <http://www.adobe.com/support/downloads/> here)
     * Adobe Acrobat 7.0.2 ( <http://www.adobe.com/support/downloads/> here)

    A vulnerability within Adobe Reader and Adobe Acrobat has been identified.
    Under certain circumstances, using XML scripts it is possible to discover
    the existence of local files.

    The vulnerability is within the Adobe Reader control. If an XML script is
    embedded in JavaScript, it is possible to discover the existence of local
    files. An attacker could then use the information gathered for malicious
    purposes.

    However the impact is minimized due to the fact that the existence of
    local files can only be discovered if the complete filenames and paths are
    known in advance by the attacker.

    More information about vulnerability:
     <http://www.securiteam.com/securitynews/6D0100A5PU.html> XXE (Xml
    eXternal Entity) Attack

    CVE Information:
     <http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1306>
    CAN-2005-1306

    ADDITIONAL INFORMATION

    The original article can be found at:
    <http://www.adobe.com/support/techdocs/331710.html>
    http://www.adobe.com/support/techdocs/331710.html

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[EXPL] IBM AIX Netpmon Privileges Escalation Vulnerability Exploit"

    Relevant Pages

    • [NEWS] Adobe Reader Embedded Font Handling Out of Bounds Array Indexing Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Adobe Reader Embedded Font Handling Out of Bounds Array Indexing ... vulnerability in Adobe System Inc.'s Adobe Reader could allow an attacker ... 12/27/2007 - Initial Vendor Notification ...
      (Securiteam)
    • [NEWS] Adobe Reader and Acrobat Multiple Stack-based Buffer Overflow Vulnerabilities
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Adobe Reader and Acrobat Multiple Stack-based Buffer Overflow ... Exploitation of these vulnerabilities would allow an attacker to execute ...
      (Securiteam)
    • [NT] Adobe Reader and Acrobat JavaScript Insecure Method Exposure Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Adobe Reader and Acrobat JavaScript Insecure Method Exposure Vulnerability ...
      (Securiteam)
    • [NEWS] Adobe Acrobat And Reader AcroJS Heap Corruption Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Adobe Acrobat And Reader AcroJS Heap Corruption Vulnerability ... Adobe Reader is "a program for viewing Portable Document Format ... memory in such a way that may lead to the execution of arbitrary code. ...
      (Securiteam)
    • [NEWS] Adobe Reader Subroutine Pointer Overwrite
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A vulnerability in Adobe Reader allows a specially crafted PDF ... Successful exploitation may allow the attacker to run arbitrary code in ...
      (Securiteam)