Overview
Adobe Acrobat contains a vulnerability in its JavaScript parsing engine that could allow an attacker to place arbitrary files on the local file system.
Description
Different versions of Adobe Acrobat software can create, modify, and read Portable Document Format (PDF) files. Acrobat JavaScript implements PDF-specific objects, methods, and properties and provides functionality similar to that of HTML client JavaScript. More information about Acrobat JavaScript is available from Acrobat 5 JavaScript Training site and in the Acrobat JavaScript Object Specification. A vulnerability in the way Acrobat 5 validates JavaScript in PDF files could allow arbitrary files to be written to any location on the local file system that is writeable by the user running Acrobat. From the Adobe Acrobat 5.0.5 Security, Accessibility, and Forms patch: |
Impact
An attacker could cause arbitrary files to be written to the local file system within the scope of the users' permissions. |
Solution
|
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.adobe.com/support/downloads/detail.jsp?ftpID=2121
- http://securityresponse.symantec.com/avcenter/venc/data/w32.yourde.html
- http://vil.nai.com/vil/content/v_100269.htm
- http://partners.adobe.com/asn/developer/training/acrobat/javascript/main.html
- http://partners.adobe.com/asn/acrobat/docs.jsp
- http://partners.adobe.com/asn/developer/pdfs/tn/5186AcroJS.pdf
Acknowledgements
This vulnerability was reported by John Landwehr of Adobe Systems Inc.
This document was written by Art Manion.
Other Information
CVE IDs: | CVE-2003-0284 |
Severity Metric: | 4.65 |
Date Public: | 2003-04-30 |
Date First Published: | 2003-05-13 |
Date Last Updated: | 2003-07-10 20:44 UTC |
Document Revision: | 35 |