>> Adobe Acrobat / Reader for Macintosh Multiple Vulnerabilities
Title : Adobe Acrobat / Reader for Macintosh Multiple Vulnerabilities VUPEN ID : VUPEN/ADV-2005-0893 CVE ID : CVE-2005-1623 - CVE-2005-1624 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-06-27
Technical Description
Two vulnerabilities were identified in Adobe Acrobat and Adobe Reader for MacOS, which could be exploited by attackers to perform certain tasks on a vulnerable system.
- The first flaw is due to an input validation error when processing JavaScript tags embedded in PDF files, which could be exploited by attackers to launch arbitrary executables on a local machine via a specially crafted PDF document. Exploitation requires that the attacker knows the exact location of the executable.
- The second issue is due to an error in the updater for Acrobat and Adobe Reader which insecurely elevates Safari Frameworks folder permissions for all users when updates are downloaded. This could be exploited by attackers to add their own frameworks.