Vulnerability Name: | CCN-11470 | ||||||
Published: | 2003-03-03 | ||||||
Updated: | 2003-03-03 | ||||||
Summary: | Adobe Acrobat Reader could allow a remote attacker to bypass signature checks, caused by a vulnerability when the Adobe Document Server for Reader Extensions is used to process a PDF file. Adobe Document Server for Reader Extensions allows owners of PDF files to assign certain rights to their PDF files. A remote attacker can submit a modified PDF file to bypass signature checks by spoofing the "Rights" Dictionary and Page Content signatures, which would allow the PDF file to be processed as a "rights-enabled" file. An attacker could use this vulnerability to enable certain features within the Acrobat Reader, such as allowing users to download, digitally sign, distribute, and submit PDF files. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||
CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||
Vulnerability Consequences: | Bypass Security | ||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Mar 03 2003 - 08:02:23 CST Implementation flaws in Adobe Document Server for Reader Extensions Source: XF Type: UNKNOWN adobe-acrobat-signature-bypass(11470) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |