|
Vulnerability like in topic (connected with vulns in xpdf). More details available here:
======
Last few weeks I was talking(mailing) with Derek (xpdf developer =96
btw. really nice guy) about some vulnerabilities in his product. 14th of
October he published path for bugs (not only my vulnerabilites) so i decide
to release advisory=85
Oryginal advisory you can find here=85 I want to write about this
vulnerabilites on blog for several reasons:
1) This is interesting bug in draw image function
2) This vulnerability exists NOT only in xpdf application
3) Adobe Acrobat Reader is vulnerable to this attack too (but ONLY Linux
version !!!)
4) Adobe Acrobat Reader didn=92t know about this bug but in his last
release fix this vulnerability.
First reason you can analyse in advisory but what about others? Vulnerable
is:
*) xpdf
*) libpoppler (so it implies vulnerability in for example evince software
=96 default pdf reader in Fedora Linux =96 I made PoC for this
software).
*) Adobe Acrobat Reader ONLY for Linux (versions up to 9.1.1 =96 9.1.2
and 9.1.3 aren=92t vuln)
*) Maybe others?
Ok let=92s analyse Adobe Acrobat vuln in version 9.1.1:
# gdb =96pid=