Title : Adobe Acrobat Reader "acroread" Insecure Temporary File Vulnerability VUPEN ID : VUPEN/ADV-2008-0765 CVE ID : CVE-2008-0883
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-03-05
Technical Description
A vulnerability has been identified in Adobe Acrobat Reader for Linux, which could be exploited by local attackers to bypass security restrictions and cause a denial of service. This issue is caused by a race condition in the "acroread" wrapper script when handling SSL certificates, which could allow malicious users to conduct symlink attacks and delete arbitrary files with the privileges of the user invoking the vulnerable script, creating a denial of service condition.