Vulnerability Name:

CVE-2002-1017 (CCN-9740)

Assigned:2002-07-30
Published:2002-07-30
Updated:2008-09-05
Summary:Adobe eBook Reader 2.1 and 2.2 allows a user to copy eBooks to other systems by using the backup feature, capturing the encryption Challenge, and using the appropriate hash function to generate the activation code.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: BugTraq Mailing List, Tue Jul 30 2002 - 09:25:05 CDT
Vulnerability: protected Adobe eBooks can be copied between computers

Source: MITRE
Type: CNA
CVE-2002-1017

Source: BUGTRAQ
Type: UNKNOWN
20020730 Vulnerability: protected Adobe eBooks can be copied between computers

Source: CCN
Type: Adobe Web site
Adobe eBook Reader

Source: XF
Type: Vendor Advisory
adobe-ebook-bypass-activation(9740)

Source: CCN
Type: OSVDB ID: 9297
Adobe eBook Reader Encryption Challenge Activation Bypass

Source: BID
Type: Vendor Advisory
5358

Source: CCN
Type: BID-5358
Adobe eBook Reader File Transfer Authorization Voucher Weak Algorithm Vulnerability

Source: CCN
Type: BID-536
Samba Pre-2.0.5 Vulnerabilities

Source: XF
Type: UNKNOWN
adobe-ebook-bypass-activation(9740)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:adobe:digital_editions:2.1:*:win:*:*:*:*:*
  • OR cpe:/a:adobe:digital_editions:2.2:*:win:*:*:*:*:*
  • OR cpe:/a:adobe:digital_editions:9.2.1:*:mac_os_x:*:*:*:*:*
  • OR cpe:/a:adobe:digital_editions:9.2.2:*:mac_os_x:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:apple:macintosh:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    adobe digital editions 2.1
    adobe digital editions 2.2
    adobe digital editions 9.2.1
    adobe digital editions 9.2.2
    apple macintosh -