Oval Definition:oval:com.redhat.rhsa:def:20080974
Revision Date:2008-11-12Version:602
Title:RHSA-2008:0974: acroread security update (Critical)
Description:Adobe Reader allows users to view and print documents in Portable Document Format (PDF).

  • Several input validation flaws were discovered in Adobe Reader. A malicious PDF file could cause Adobe Reader to crash or, potentially, execute arbitrary code as the user running Adobe Reader. (CVE-2008-2549, CVE-2008-2992, CVE-2008-4812, CVE-2008-4813, CVE-2008-4814, CVE-2008-4817)

  • The Adobe Reader binary had an insecure relative RPATH (runtime library search path) set in the ELF (Executable and Linking Format) header. A local attacker able to convince another user to run Adobe Reader in an attacker-controlled directory could run arbitrary code with the privileges of the victim. (CVE-2008-4815)

    All acroread users are advised to upgrade to these updated packages, that contain Adobe Reader version 8.1.3, and are not vulnerable to these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-2549
    CVE-2008-2992
    CVE-2008-4812
    CVE-2008-4813
    CVE-2008-4814
    CVE-2008-4815
    CVE-2008-4817
    CVE-2009-0927
    RHSA-2008:0974-01
    Platform(s):Supplementary for Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux 5 is installed
  • AND Package Information
  • acroread is earlier than 0:8.1.3-1.el5
  • AND acroread is signed with Red Hat redhatrelease key
  • OR
  • acroread-plugin is earlier than 0:8.1.3-1.el5
  • AND acroread-plugin is signed with Red Hat redhatrelease key
  • BACK