adobe reader 8.1.4 / 9.1 spell.customDictionaryOpen() remote code execution

Moderators: Moderator, Global Moderator

Post Reply
Riftt

adobe reader 8.1.4 / 9.1 spell.customDictionaryOpen() remote code execution

Post by Riftt »

Versions 8.1.4 and 9.1 of Adobe Reader for linux are vulnerable to remote code execution. the following link jumps to a brief overview of the situation.
http://www.securityfocus.com/bid/34740/discuss

currently there are no patches supplied as the vendor is investigating this issue, they say that 9.1 is not vulnerable however im running 9.1 and successfully jumped to a custom specified eip containing the shellcode supplied by the POC . If you are running this version of adobe on a linux box my suggestion is if you dont trust the site you are getting a PDF from, be sure to either turn off the browser plugin for pdf's so it will not automatically run them, and be sure to first download the pdf to your hdd. For those who do not know, remote code execution is a serious problem. Basically whatever you could do sitting at your computer, a remote attacker could also perform on your machine, and i dont mean just solitaire. You can spawn shells, format discs, you name it.
I will keep an eye out for a vendor supplied patch or similar update to post here. The vendor does claim there will be a patch by tuesday the 12th of may.

Be Safe.
Post Reply

Return to “Security”