CERT-In Vulnerability Note
CIVN-2006-0123
Adobe Reader / Acrobat AcroPDF ActiveX Control Vulnerability
Original Issue Date:December 01, 2006
Severity Rating: HIGH
Systems Affected
- Adobe Acrobat 7.x running along with Internet Explorer.
- Adobe Reader 7.x running along with Internet Explorer.
Overview
A vulnerability has been reported in Adobe Reader and Adobe Acrobat that could be exploited by an attacker to take complete control of the vulnerable system.
Description
The vulnerability is caused due to errors in the AcroPDF ActiveX control AcroPDF.dll when processing arbitrary arguments passed to the "setPageMode ", "setLayoutMode ", "setNamedDest ", and "LoadFile " methods. The ActiveX control AcroPDF is used by Internet Explorer.
The attacker could exploit this vulnerability by creating and hosting a specially crafted web page and could persuade a user to visit the web page and could crash the application. It may be noted that the systems running Internet Explorer are vulnerable, systems running other web browsers are not vulnerable.
Workaround
Prevent PDF documents from opening within an Internet Explorer window by following the steps: - Exit Internet Explorer and Adobe Reader.
- Browse to <volume>:\Program Files\Adobe\Acrobat 7.0\ActiveX.
Note: If you did not install Acrobat to the default location, browse to the location of your Acrobat 7.0 folder - Select AcroPDF.dll and delete it.
Disable ActiveX while visiting untrusted websites. Do not follow unsolicited links.
References
Adobe
http://www.adobe.com/support/security/advisories/apsa06-02.html
Secunia
http://secunia.com/advisories/23138/
USCERT
http://www.kb.cert.org/vuls/id/198908
CVE Name
CVE-2006-6027
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|