Lucene search

K
redhatRedHatRHSA-2008:0641
HistoryJul 21, 2008 - 12:00 a.m.

(RHSA-2008:0641) Critical: acroread security update

2008-07-2100:00:00
access.redhat.com
13

0.34 Low

EPSS

Percentile

97.1%

Adobe Acrobat Reader allows users to view and print documents in Portable
Document Format (PDF).

An input validation flaw was discovered in a JavaScript engine used by
Acrobat Reader. A malicious PDF file could cause Acrobat Reader to crash
or, potentially, execute arbitrary code as the user running Acrobat Reader.
(CVE-2008-2641)

An insecure temporary file usage issue was discovered in the Acrobat Reader
“acroread” startup script. A local attacker could potentially overwrite
arbitrary files that were writable by the user running Acrobat Reader, if
the victim ran “acroread” with certain command line arguments.
(CVE-2008-0883)

All acroread users are advised to upgrade to these updated packages, that
contain Acrobat Reader version 8.1.2 Security Update 1, and are not
vulnerable to these issues.

OSVersionArchitecturePackageVersionFilename
RedHat5i386acroread-plugin< 8.1.2.SU1-2.el5acroread-plugin-8.1.2.SU1-2.el5.i386.rpm
RedHat5i386acroread< 8.1.2.SU1-2.el5acroread-8.1.2.SU1-2.el5.i386.rpm

0.34 Low

EPSS

Percentile

97.1%